Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-48807

27 дней назад

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-48807

27 дней назад

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-48807

27 дней назад

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __to ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-8x9c-rmqh-456c

около 1 месяца назад

Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-48807

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.

CVSS3: 9.1
0%
Низкий
27 дней назад
nvd логотип
CVE-2026-48807

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.

CVSS3: 9.1
0%
Низкий
27 дней назад
debian логотип
CVE-2026-48807

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __to ...

CVSS3: 9.1
0%
Низкий
27 дней назад
github логотип
GHSA-8x9c-rmqh-456c

Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters

0%
Низкий
около 1 месяца назад

Уязвимостей на страницу