Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-49981

Опубликовано: 14 июл. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.2

Описание

Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0.

РелизСтатусПримечание
devel

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

jammy

DNE

noble

DNE

resolute

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 12%
0.00212
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
26 дней назад

Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0.

CVSS3: 8.2
debian
26 дней назад

Twig is a template language for PHP. Prior to 3.27.0, the per-template ...

github
около 1 месяца назад

Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`

EPSS

Процентиль: 12%
0.00212
Низкий

8.2 High

CVSS3