Security News

Cybersecurity news aggregator

🐧
HIGH Vulnerabilities Ubuntu Security

USN-8408-1: Twig vulnerability

A vulnerability (CVE-2026-24425, CVSS 8.8 HIGH) in the Twig PHP template engine allows authenticated users to execute arbitrary code via specially crafted network traffic by exploiting improper validation of PHP callables when using a source policy. According to NVD data, affected versions are Symfony Twig 2.16.0 through 2.16.1 and 3.9.0 through versions prior to 3.26.0. The fixed version is Twig 3.26.0.
Read Full Article →

Ubuntu Security Notices USN-8408-1 USN-8408-1: Twig vulnerability Publication date 8 June 2026 Overview Twig could be made to run programs if it received specially crafted network traffic from an authenticated user. Releases 26.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages php-twig - Flexible, fast, and secure template engine for PHP Details It was discovered that Twig did not properly validate PHP callables when using a source policy. An authenticated user could possibly use this issue to execute arbitrary code. It was discovered that Twig did not properly validate PHP callables when using a source policy. An authenticated user could possibly use this issue to execute arbitrary code. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 26.04 LTS resolute php-twig – 3.23.0-2ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-24425 CVE-2026-24425

Share this article