Количество 4
Количество 4
CVE-2026-47732
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional expressions, comparison operators, tests, template-loading tags, dynamic attribute names, spread arguments, the do tag, and the .. range operator. This issue is fixed in version 3.26.0.
CVE-2026-47732
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional expressions, comparison operators, tests, template-loading tags, dynamic attribute names, spread arguments, the do tag, and the .. range operator. This issue is fixed in version 3.26.0.
CVE-2026-47732
Twig is a template language for PHP. Prior to 3.26.0, several Twig lan ...
GHSA-pr2w-4gpj-cpq4
Twig: Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-47732 Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional expressions, comparison operators, tests, template-loading tags, dynamic attribute names, spread arguments, the do tag, and the .. range operator. This issue is fixed in version 3.26.0. | CVSS3: 6.5 | 0% Низкий | 27 дней назад | |
CVE-2026-47732 Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional expressions, comparison operators, tests, template-loading tags, dynamic attribute names, spread arguments, the do tag, and the .. range operator. This issue is fixed in version 3.26.0. | CVSS3: 6.5 | 0% Низкий | 27 дней назад | |
CVE-2026-47732 Twig is a template language for PHP. Prior to 3.26.0, several Twig lan ... | CVSS3: 6.5 | 0% Низкий | 27 дней назад | |
GHSA-pr2w-4gpj-cpq4 Twig: Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу