CVE-2023-46734: Debian Linux
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.
Affected products
- Debian Debian Linux: version 10.0 only
- Sensiolabs Symfony: from 2.0.0, before 4.4.51 (fixed in 4.4.51); from 5.0.0, before 5.4.31 (fixed in 5.4.31); from 6.0.0, before 6.3.8 (fixed in 6.3.8)
- Symfony Twig-Bridge: from 2.0.0, before 4.4.51 (fixed in 4.4.51); from 5.0.0, before 5.4.31 (fixed in 5.4.31); from 6.0.0, before 6.3.8 (fixed in 6.3.8)
Published 2023-11-10. Last modified 2026-07-29.