Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-46627

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Версия до 3.26.0 (исключая)

EPSS

Процентиль: 31%
0.00385
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.5
ubuntu
28 дней назад

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.

CVSS3: 6.5
debian
28 дней назад

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox ...

EPSS

Процентиль: 31%
0.00385
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400