UBUNTU-CVE-2026-24425

Source
https://ubuntu.com/security/CVE-2026-24425
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-24425.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-24425
Upstream
Downstream
Related
Published
2026-05-20T14:16:00Z
Modified
2026-06-09T03:15:06Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.

References

Affected packages

Ubuntu:25.10 / php-twig

Package

Name
php-twig
Purl
pkg:deb/ubuntu/php-twig?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.20.0-2ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "php-twig",
            "binary_version": "3.20.0-2ubuntu1"
        },
        {
            "binary_name": "php-twig-cache-extra",
            "binary_version": "3.20.0-2ubuntu1"
        },
        {
            "binary_name": "php-twig-cssinliner-extra",
            "binary_version": "3.20.0-2ubuntu1"
        },
        {
            "binary_name": "php-twig-extra-bundle",
            "binary_version": "3.20.0-2ubuntu1"
        },
        {
            "binary_name": "php-twig-html-extra",
            "binary_version": "3.20.0-2ubuntu1"
        },
        {
            "binary_name": "php-twig-inky-extra",
            "binary_version": "3.20.0-2ubuntu1"
        },
        {
            "binary_name": "php-twig-intl-extra",
            "binary_version": "3.20.0-2ubuntu1"
        },
        {
            "binary_name": "php-twig-markdown-extra",
            "binary_version": "3.20.0-2ubuntu1"
        },
        {
            "binary_name": "php-twig-string-extra",
            "binary_version": "3.20.0-2ubuntu1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-24425.json"

Ubuntu:Pro:26.04:LTS / php-twig

Package

Name
php-twig
Purl
pkg:deb/ubuntu/php-twig?arch=source&distro=esm-apps%2Fresolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.23.0-2ubuntu0.1~esm1

Affected versions

3.*
3.20.0-2ubuntu1
3.23.0-2build5
3.23.0-2build7

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "php-twig",
            "binary_version": "3.23.0-2ubuntu0.1~esm1"
        },
        {
            "binary_name": "php-twig-cache-extra",
            "binary_version": "3.23.0-2ubuntu0.1~esm1"
        },
        {
            "binary_name": "php-twig-cssinliner-extra",
            "binary_version": "3.23.0-2ubuntu0.1~esm1"
        },
        {
            "binary_name": "php-twig-extra-bundle",
            "binary_version": "3.23.0-2ubuntu0.1~esm1"
        },
        {
            "binary_name": "php-twig-html-extra",
            "binary_version": "3.23.0-2ubuntu0.1~esm1"
        },
        {
            "binary_name": "php-twig-inky-extra",
            "binary_version": "3.23.0-2ubuntu0.1~esm1"
        },
        {
            "binary_name": "php-twig-intl-extra",
            "binary_version": "3.23.0-2ubuntu0.1~esm1"
        },
        {
            "binary_name": "php-twig-markdown-extra",
            "binary_version": "3.23.0-2ubuntu0.1~esm1"
        },
        {
            "binary_name": "php-twig-string-extra",
            "binary_version": "3.23.0-2ubuntu0.1~esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-24425.json"