-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 27 May 2026 23:07:15 +0200
Source: php-twig
Architecture: source
Version: 3.27.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian PHP PEAR Maintainers <pkg-php-pear@lists.alioth.debian.org>
Changed-By: David Prévot <taffit@debian.org>
Changes:
php-twig (3.27.0-1) unstable; urgency=medium
.
[ Fabien Potencier ]
* Fix sandbox bypass in deprecated internal wrappers [CVE-2026-48805]
* Fix sandbox bypass in the "column" filter under SourcePolicyInterface
[CVE-2026-48808]
* Fix sandbox __toString bypass via Traversable in join/replace filters
* Fix sandbox `__toString` bypass via the `in` and `not in` operators
[CVE-2026-48807]
* Fix sandbox __toString policy bypass via dynamic mapping keys
[CVE-2026-48806]
* Fix sandbox filter/tag/function allow-list bypass when sandbox state
changes between renders [CVE-2026-46636]
* Prepare the 3.27.0 release
.
[ David Prévot ]
* Add missing space in previous changelog entry
Checksums-Sha1:
b7207df990448664ec7fa08f72525e0b30ae5124 2949 php-twig_3.27.0-1.dsc
65958235ae13b3d5df88b4597cb8f9275c2b86ec 295220 php-twig_3.27.0.orig.tar.xz
09c78f73c320f049235111dc32831719bea7fd89 33528 php-twig_3.27.0-1.debian.tar.xz
0cd421c71863d56326b54f483aa5226792c3c396 12840 php-twig_3.27.0-1_amd64.buildinfo
Checksums-Sha256:
deb6a25d9bd84253254560465b8645b8babd71ad088c058b8a2a1ede45fe9032 2949 php-twig_3.27.0-1.dsc
34c8a7e6570787bb9f3502d991832c42d5066f008132c2cad09b5d793c775705 295220 php-twig_3.27.0.orig.tar.xz
b74e8d3ce9f2b7d8d1327c0d1f1564fd7fb4fb7ce4b0440535e38c7c82cd8796 33528 php-twig_3.27.0-1.debian.tar.xz
96b6309374a2d6e536b4d17b1064bb407481de55a3c547402f6b135693b37e6a 12840 php-twig_3.27.0-1_amd64.buildinfo
Files:
16bf4d7f0d3ee0db3e2920083e0046ca 2949 php optional php-twig_3.27.0-1.dsc
a0fd43ce95ac7a80c70bf85b89ce6859 295220 php optional php-twig_3.27.0.orig.tar.xz
fe3b9bd2aee91baf2c0b37ee100bfe58 33528 php optional php-twig_3.27.0-1.debian.tar.xz
218d0e75631780d381ea85cb389dd6b0 12840 php optional php-twig_3.27.0-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQFGBAEBCgAwFiEEeHVNB7wJXHRI941mBYwc+UT2vTwFAmoXYSMSHHRhZmZpdEBk
ZWJpYW4ub3JnAAoJEAWMHPlE9r08SaMH/0RcjOj1EplStFjdOuGfoomh25DabKgz
M7SR5sUd/sAxK0meuu0OFoZ2QNV5nIqCsb/HTl7gDcGg/dcvyoGyooOt8SVxPBXC
h8cXdBmMsix9MuLMWsEfrF1QF92IId/UB6pMvrrF4B6EvBQ/l+PLIoEVVVkO2ONK
FDRJ1xCl85RjzRkKscdpNavrk3hiOk10yKC3c3bUR4pfgDqbx0VV3ksDoRFlv0Hy
D54TwNy37fMnAb5oohhYam9AOPoT6KRZlWrxSOmtJvjhjXId/MmS8Us/JLUnd9EY
yoODj1CShPL8zzhZYEj8dA9D7Odbiip8D8AVFHAL4MK6TrIJ/RvUCyI=
=meQM
-----END PGP SIGNATURE-----