Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-46629

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as locale, pattern, and attrs, allowing a template to allocate many ICU formatter objects that remain pinned for the lifetime of the Twig\Environment. This issue is fixed in version 3.26.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
Версия до 3.26.0 (исключая)

EPSS

Процентиль: 22%
0.00302
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 6.5
ubuntu
28 дней назад

Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as locale, pattern, and attrs, allowing a template to allocate many ICU formatter objects that remain pinned for the lifetime of the Twig\Environment. This issue is fixed in version 3.26.0.

CVSS3: 6.5
debian
28 дней назад

Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra ...

github
3 месяца назад

twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments

EPSS

Процентиль: 22%
0.00302
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770