-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 27 May 2026 23:07:15 +0200 Source: php-twig Architecture: source Version: 3.27.0-1 Distribution: unstable Urgency: medium Maintainer: Debian PHP PEAR Maintainers <[email protected]> Changed-By: David Prévot <[email protected]> Changes: php-twig (3.27.0-1) unstable; urgency=medium . [ Fabien Potencier ] * Fix sandbox bypass in deprecated internal wrappers [CVE-2026-48805] * Fix sandbox bypass in the "column" filter under SourcePolicyInterface [CVE-2026-48808] * Fix sandbox __toString bypass via Traversable in join/replace filters * Fix sandbox `__toString` bypass via the `in` and `not in` operators [CVE-2026-48807] * Fix sandbox __toString policy bypass via dynamic mapping keys [CVE-2026-48806] * Fix sandbox filter/tag/function allow-list bypass when sandbox state changes between renders [CVE-2026-46636] * Prepare the 3.27.0 release . [ David Prévot ] * Add missing space in previous changelog entry Checksums-Sha1: b7207df990448664ec7fa08f72525e0b30ae5124 2949 php-twig_3.27.0-1.dsc 65958235ae13b3d5df88b4597cb8f9275c2b86ec 295220 php-twig_3.27.0.orig.tar.xz 09c78f73c320f049235111dc32831719bea7fd89 33528 php-twig_3.27.0-1.debian.tar.xz 0cd421c71863d56326b54f483aa5226792c3c396 12840 php-twig_3.27.0-1_amd64.buildinfo Checksums-Sha256: deb6a25d9bd84253254560465b8645b8babd71ad088c058b8a2a1ede45fe9032 2949 php-twig_3.27.0-1.dsc 34c8a7e6570787bb9f3502d991832c42d5066f008132c2cad09b5d793c775705 295220 php-twig_3.27.0.orig.tar.xz b74e8d3ce9f2b7d8d1327c0d1f1564fd7fb4fb7ce4b0440535e38c7c82cd8796 33528 php-twig_3.27.0-1.debian.tar.xz 96b6309374a2d6e536b4d17b1064bb407481de55a3c547402f6b135693b37e6a 12840 php-twig_3.27.0-1_amd64.buildinfo Files: 16bf4d7f0d3ee0db3e2920083e0046ca 2949 php optional php-twig_3.27.0-1.dsc a0fd43ce95ac7a80c70bf85b89ce6859 295220 php optional php-twig_3.27.0.orig.tar.xz fe3b9bd2aee91baf2c0b37ee100bfe58 33528 php optional php-twig_3.27.0-1.debian.tar.xz 218d0e75631780d381ea85cb389dd6b0 12840 php optional php-twig_3.27.0-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE----- iQFGBAEBCgAwFiEEeHVNB7wJXHRI941mBYwc+UT2vTwFAmoXYSMSHHRhZmZpdEBk ZWJpYW4ub3JnAAoJEAWMHPlE9r08SaMH/0RcjOj1EplStFjdOuGfoomh25DabKgz M7SR5sUd/sAxK0meuu0OFoZ2QNV5nIqCsb/HTl7gDcGg/dcvyoGyooOt8SVxPBXC h8cXdBmMsix9MuLMWsEfrF1QF92IId/UB6pMvrrF4B6EvBQ/l+PLIoEVVVkO2ONK FDRJ1xCl85RjzRkKscdpNavrk3hiOk10yKC3c3bUR4pfgDqbx0VV3ksDoRFlv0Hy D54TwNy37fMnAb5oohhYam9AOPoT6KRZlWrxSOmtJvjhjXId/MmS8Us/JLUnd9EY yoODj1CShPL8zzhZYEj8dA9D7Odbiip8D8AVFHAL4MK6TrIJ/RvUCyI= =meQM -----END PGP SIGNATURE-----
pgpMwqlOcMjIE.pgp
Description: PGP signature

