[From nobody Tue Jun  2 20:19:41 2026
Received: (at 1086884-close) by bugs.debian.org; 2 Jun 2026 19:17:20 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-114.1 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,
 FVGT_m_MULTI_ODD,HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,
 USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 111; hammy, 150; neutral, 142; spammy,
 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz,
 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from muffat.debian.org ([2607:f8f0:614:1::1274:33]:38946)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wUUc4-00Akh6-1T for 1086884-close@bugs.debian.org;
 Tue, 02 Jun 2026 19:17:20 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by muffat.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wUUc4-004Ra2-1E for 1086884-close@bugs.debian.org;
 Tue, 02 Jun 2026 19:17:20 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=M3TW1OQ8k76y6xftGtxgW/foRiqOrj5Q1RV61qpvLQE=; b=ttLqYXlNVuP5Kc8o9YLpoFxWxw
 6QU7n1gW0X05Omxp91jmud3I3dlAETE1dAnXPwrw58N0C5vp2oK/OyE1pF4IDvR1Q5SVStVqheMVA
 metT9TQU2aGlXNyObCm4nYglt0ONb15K6AVwClmFrWqoo7oh4oPaLqDVz4tPV+eGWvGtBbE/sSfqw
 cN30i8mdEacbe2b+GaAx+OIB1uO3xDxQ8j/cfegj6E6/+gGFsVLux+1jz8ZBRDx2Q6L+XlttaRQcu
 0LuMZfLEeZ+W7VPHaAYeXCmJHfUl7TGtX2F6PAQNsWN1TLVXenSdO5JHBIBHJPzEADLqeThkjujSm
 Nbv/SYcQ==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wUUc3-000000061GA-2R1p; Tue, 02 Jun 2026 19:17:19 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: =?utf-8?q?David_Pr=C3=A9vot?= &lt;taffit@debian.org&gt;
To: 1086884-close@bugs.debian.org
X-DAK: dak process-policy
X-Debian: DAK
X-Debian-Package: php-twig
Debian: DAK
Debian-Changes: php-twig_3.5.1-1+deb12u2_source.changes
Debian-Source: php-twig
Debian-Version: 3.5.1-1+deb12u2
Debian-Architecture: source
Debian-Suite: oldstable-proposed-updates
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1086884: fixed in php-twig 3.5.1-1+deb12u2
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============0115700735012334157==&quot;
Message-Id: &lt;E1wUUc3-000000061GA-2R1p@fasolo.debian.org&gt;
Date: Tue, 02 Jun 2026 19:17:19 +0000

--===============0115700735012334157==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: php-twig
Source-Version: 3.5.1-1+deb12u2
Done: David Pr=C3=A9vot &lt;taffit@debian.org&gt;

We believe that the bug you reported is fixed in the latest version of
php-twig, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1086884@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
David Pr=C3=A9vot &lt;taffit@debian.org&gt; (supplier of updated php-twig package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 02 Jun 2026 05:22:19 +0200
Source: php-twig
Architecture: source
Version: 3.5.1-1+deb12u2
Distribution: bookworm-security
Urgency: medium
Maintainer: Debian PHP PEAR Maintainers &lt;pkg-php-pear@lists.alioth.debian.org&gt;
Changed-By: David Pr=C3=A9vot &lt;taffit@debian.org&gt;
Closes: 1086884
Changes:
 php-twig (3.5.1-1+deb12u2) bookworm-security; urgency=3Dmedium
 .
   * Backport security fixes from upstream
     - Fix sandbox handling for __toString() [CVE-2024-51754]
       (Closes: #1086884)
     - Pre-escape HTML input on the `spaceless` [CVE-2026-46628]
     - Fix unbounded memoisation of `IntlDateFormatter` / `NumberFormatter`
       [CVE-2026-46629]
     - Fix sandbox bypass: PHP code injection via {% use %} template name
       [CVE-2026-46633]
     - Fix XSS and pre-escape input on HTML-emitting filters in the extras
       [CVE-2026-46637]
     - [Profiler] Escape template and profile names in `HtmlDumper`
       [CVE-2026-47730]
   * Update expected output with php-symfony-intl latest update
Checksums-Sha1:
 44e1668f485bdc8dc42a4d2264072bf964c2ed14 2910 php-twig_3.5.1-1+deb12u2.dsc
 a7c3f886bff99952262bb9b3bab9fd62c2fadaf5 26476 php-twig_3.5.1-1+deb12u2.debi=
an.tar.xz
 3854c1a47a7d96a0a192a1e81b627bf870abf7be 14295 php-twig_3.5.1-1+deb12u2_amd6=
4.buildinfo
Checksums-Sha256:
 65e9b2f450d3093b058f5dbab926fb5577e595dbd98b1b1c8e86e413c6f53342 2910 php-tw=
ig_3.5.1-1+deb12u2.dsc
 9497fd3c1c8ad90e38a8e772e33ab2c0c9815318ad116e3988c965c846620c21 26476 php-t=
wig_3.5.1-1+deb12u2.debian.tar.xz
 d0a3c69e8c25cce58f9cf2b99107f98924b8efac3192712a20366e037b818cb3 14295 php-t=
wig_3.5.1-1+deb12u2_amd64.buildinfo
Files:
 b8a51bb78d260303637e9443c5ff5e6b 2910 php optional php-twig_3.5.1-1+deb12u2.=
dsc
 80a9984d1f60e3f754fbc75169490515 26476 php optional php-twig_3.5.1-1+deb12u2=
.debian.tar.xz
 edb32a0afb6c03980c434b0cc94eb485 14295 php optional php-twig_3.5.1-1+deb12u2=
_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQFGBAEBCgAwFiEEeHVNB7wJXHRI941mBYwc+UT2vTwFAmoewCoSHHRhZmZpdEBk
ZWJpYW4ub3JnAAoJEAWMHPlE9r08ZM8H+wTTGVJsuZQtcfkuueXBDfWyR76JHYAe
8lJDSnGZ5O+1Sm5ucjPbDvEKKI8uTTAQJDE+ppAm95evx1yaay2JZXid8JNnzRS7
Cg6tXF7OiypM8EUK6YvCYYuqIZ37CiRc3zr4m/4/CMh9DeOaKzj1W5WH5CVuM5UX
4KTWgqI0tKNx7En+wv0BtKiBy1SM/D5vlKwDSkQTx3r6FyfiqS+EaNNSGOPCWj69
x2zpXuhVR/hXHfIgSv/kOitbiR9NXdMt27oEczTg/a3N0Fn4eUfkRfzIyCjZIHjn
0QA3YYNJQGqcj33sWwCammnPvvgsi/rtx8jkAaoUI/kjwKDyvo/544Q=3D
=3DiwHk
-----END PGP SIGNATURE-----


--===============0115700735012334157==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCah8sPwAKCRCb9qggYcy5
IdjcAQC8FG7XZHdGXCz8MV4slHzKNTazULdKBCHwsNmnyrx5IAD+JE5pu6oYS0Qc
d1cxDVZW6H+TXM5CAgSqJEfyBRsndw8=
=hykg
-----END PGP SIGNATURE-----

--===============0115700735012334157==--
]