Bug 2500740 (CVE-2026-46639) - CVE-2026-46639 twig/twig: Twig: Sandbox bypass allows information disclosure and method invocation
Summary: CVE-2026-46639 twig/twig: Twig: Sandbox bypass allows information disclosure ...
Keywords:
Status: NEW
Alias: CVE-2026-46639
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-14 22:03 UTC by OSIDB Bzimport
Modified: 2026-07-15 11:35 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-14 22:03:49 UTC
Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template to read public properties or invoke public getters on objects passed to the template engine. This issue is fixed in version 3.26.0.


Note You need to log in before you can comment on or make changes to this bug.