CVE-2023-46734: Debian Linux

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Sensiolabs Symfony: from 2.0.0, before 4.4.51 (fixed in 4.4.51); from 5.0.0, before 5.4.31 (fixed in 5.4.31); from 6.0.0, before 6.3.8 (fixed in 6.3.8)
  • Symfony Twig-Bridge: from 2.0.0, before 4.4.51 (fixed in 4.4.51); from 5.0.0, before 5.4.31 (fixed in 5.4.31); from 6.0.0, before 6.3.8 (fixed in 6.3.8)

Published 2023-11-10. Last modified 2026-07-29.