CVE-2026-46627 UNKNOWN

CVE-2026-46627

Published: 2026-07-14

Description

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…