{"id":"CVE-2026-49981","aliases":["GHSA-529h-vh3j-85hq"],"url":"https://o3.security/vulnerability/CVE-2026-49981","summary":"Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`","details":"Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0.","published":"2026-07-14T21:26:00.460Z","modified":"2026-08-12T03:51:48.147024024Z","cvss":null,"epss":{"score":0.00362,"percentile":0.2887,"asOf":"2026-08-25"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"twig/twig","fixedVersion":"3.27.0"}],"fix":{"url":"https://github.com/twigphp/Twig/commit/23eb6eb1267cb0d303b91eb5cff9b0c559c538a4","label":"twigphp/Twig@23eb6eb"},"references":[{"type":"WEB","url":"https://github.com/twigphp/Twig/releases/tag/v3.27.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49981.json"},{"type":"ADVISORY","url":"https://github.com/twigphp/Twig/security/advisories/GHSA-529h-vh3j-85hq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49981"},{"type":"FIX","url":"https://github.com/twigphp/Twig/commit/23eb6eb1267cb0d303b91eb5cff9b0c559c538a4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.147024024Z"}}