symfony security advisories
5 threat alerts tracking vulnerabilities and security advisories that affect symfony products.
Vulnios monitors symfony CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent symfony security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2026-48805 — symfony — twig
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and a
criticalCVE-2026-48805Critical Vulnerability: CVE-2026-48806 — symfony — twig
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used a
criticalCVE-2026-48806Critical Vulnerability: CVE-2026-48807 — symfony — twig
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not i
criticalCVE-2026-48807Critical Vulnerability: CVE-2026-46633 — symfony — twig
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, al
criticalCVE-2026-46633Critical Vulnerability: CVE-2026-46634 — symfony — twig
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyI
criticalCVE-2026-46634
Track symfony exposure across your environment
Vulnios automatically cross-references your asset inventory against new symfony CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan