{"id":"CVE-2026-46629","aliases":["GHSA-35wc-cvqg-78fp"],"url":"https://o3.security/vulnerability/CVE-2026-46629","summary":"Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments","details":"### Description\n\n`IntlExtension` memoises every `\\IntlDateFormatter` and `\\NumberFormatter` it creates in instance-level arrays keyed on a hash that includes `locale`, `pattern`, `attrs` and other values that are ordinary named arguments of the `format_datetime` / `format_date` / `format_time` / `format_number` / `format_currency` filters. There is no size limit and no eviction.\n\nA template that iterates over many distinct `pattern` (or `locale`, or `grouping_used`, ...) values therefore allocates one ICU formatter object per distinct value and pins it for the entire lifetime of the `Twig\\Environment`. Because ICU allocates its backing buffers outside the Zend memory manager, this growth is not bounded by `memory_limit`. On long-running runtimes (RoadRunner, Swoole, FrankenPHP worker mode, ReactPHP) where the `Environment` outlives a single request, the cache also accumulates across requests.\n\n### Resolution\n\nThe formatter caches are now bounded in size (100 entries each) and evict on a FIFO basis.\n\n### Credits\n\nTwig would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.","published":"2026-07-14T21:22:15.595Z","modified":"2026-08-12T03:51:33.187726234Z","cvss":null,"epss":{"score":0.00302,"percentile":0.22778,"asOf":"2026-08-18"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"twig/intl-extra","fixedVersion":"3.26.0"}],"fix":{"url":"https://github.com/twigphp/Twig/commit/6add9066fc5c0455eb764c1f3af6e4e4e3562419","label":"twigphp/Twig@6add906"},"references":[{"type":"WEB","url":"https://github.com/twigphp/Twig/releases/tag/v3.26.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46629.json"},{"type":"ADVISORY","url":"https://github.com/twigphp/Twig/security/advisories/GHSA-35wc-cvqg-78fp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46629"},{"type":"FIX","url":"https://github.com/twigphp/Twig/commit/6add9066fc5c0455eb764c1f3af6e4e4e3562419"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/intl-extra/CVE-2026-46629.yaml"},{"type":"PACKAGE","url":"https://github.com/twigphp/Twig"},{"type":"WEB","url":"https://symfony.com/cve-2026-46629"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:33.187726234Z"}}