Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-46640

Опубликовано: 14 июл. 2026
Источник: debian
EPSS Низкий

Описание

Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the generated template source and executed at template-load time. This issue is fixed in version 3.26.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php-twigfixed3.26.0-1package
php-twignot-affectedbookwormpackage
php-twignot-affectedbullseyepackage

Примечания

  • https://symfony.com/blog/cve-2026-46640-arbitrary-php-code-execution-via-self-string-macro-reference-compilation

EPSS

Процентиль: 33%
0.00405
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
28 дней назад

Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the generated template source and executed at template-load time. This issue is fixed in version 3.26.0.

CVSS3: 8.8
nvd
28 дней назад

Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the generated template source and executed at template-load time. This issue is fixed in version 3.26.0.

github
3 месяца назад

Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation

EPSS

Процентиль: 33%
0.00405
Низкий