CVE-2026-46633: Symfony Twig
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.
Affected products
- Symfony Twig: before 3.26.0 (fixed in 3.26.0)
Published 2026-07-14. Last modified 2026-07-16.