Package impact
COMPOSER / twig/twig
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2026-46639 | high | — | 8.0 | 8d ago | Twig: Sandbox property and method bypass via object-destructuring assignment | |
| CVE-2026-46640 | high | — | 8.0 | 8d ago | Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation |