CVE-2019-9942: Debian Linux
Low severity, CVSS 3.7. EPSS: 1.4% chance of exploitation in the next 30 days.
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
Affected products
- Debian Debian Linux: version 9.0 only
- Symfony Twig: before 1.38.0 (fixed in 1.38.0); from 2.0.0, before 2.7.0 (fixed in 2.7.0)
Published 2019-03-23. Last modified 2026-06-17.