[Git][security-tracker-team/security-tracker][master] mark two twig issues as unimportant

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon May 25 18:53:38 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
efdc3ca4 by Moritz Muehlenhoff at 2026-05-25T19:53:29+02:00
mark two twig issues as unimportant

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1116,10 +1116,11 @@ CVE-2026-47732
 	NOTE: https://github.com/twigphp/Twig/security/advisories/GHSA-pr2w-4gpj-cpq4
 	NOTE: https://symfony.com/blog/cve-2026-47732-sandbox-multiple-tostring-policy-bypasses-via-unguarded-string-coercion-points
 CVE-2026-46634
-	- php-twig 3.26.0-1
+	- php-twig 3.26.0-1 (unimportant)
 	[bookworm] - php-twig <not-affected> (Vulnerable code not present, introduced in 3.9.0)
 	[bullseye] - php-twig <not-affected> (Vulnerable code not present, introduced in 3.9.0)
 	NOTE: https://symfony.com/blog/cve-2026-46634-template-from-string-escapes-a-sourcepolicy-driven-sandbox-via-synthesized-template-name
+	NOTE: Upstream change only clarifies the documentation
 CVE-2026-46627
 	- php-twig 3.26.0-1
 	NOTE: https://symfony.com/blog/cve-2026-46627-sandbox-does-not-protect-against-resource-exhaustion
@@ -1127,8 +1128,9 @@ CVE-2026-46635
 	- php-twig 3.26.0-1
 	NOTE: https://symfony.com/blog/cve-2026-46635-sandbox-property-allowlist-bypass-via-the-column-filter-array-column-on-objects
 CVE-2026-46628
-	- php-twig 3.26.0-1
+	- php-twig 3.26.0-1 (unimportant)
 	NOTE: https://symfony.com/blog/cve-2026-46628-the-spaceless-filter-implicitly-marks-its-output-as-safe
+	NOTE: Upstream change only clarifies the documentation
 CVE-2026-46629
 	- php-twig 3.26.0-1
 	NOTE: https://symfony.com/blog/cve-2026-46629-unbounded-formatter-memoisation-in-twig-intl-extra-keyed-on-template-controlled-arguments



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/efdc3ca45e5b7c6610708bc3ea37bb6c9fb1102b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/efdc3ca45e5b7c6610708bc3ea37bb6c9fb1102b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260525/b474aefd/attachment.htm>


More information about the debian-security-tracker-commits mailing list