CVE-2019-9942: Debian Linux

Low severity, CVSS 3.7. EPSS: 1.4% chance of exploitation in the next 30 days.

A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Symfony Twig: before 1.38.0 (fixed in 1.38.0); from 2.0.0, before 2.7.0 (fixed in 2.7.0)

Published 2019-03-23. Last modified 2026-06-17.