CVE-2026-46629: Symfony Twig

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as locale, pattern, and attrs, allowing a template to allocate many ICU formatter objects that remain pinned for the lifetime of the Twig\Environment. This issue is fixed in version 3.26.0.

Affected products

  • Symfony Twig: before 3.26.0 (fixed in 3.26.0)

Published 2026-07-14. Last modified 2026-07-16.