🔐 CVE-2026-46637: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']` ➡️ https://symfony.com/blog/cve-2026-46637-html-output-filters-in-twig-extras-incorrectly-declared-is-safe-all
Post summary
The tweet announces the discovery of CVE-2026-46637 in Symfony Twig extras, describing an issue with incorrectly marked safe HTML filters, but provides no proof‑of‑concept, exploit code, active exploitation evidence, or patch details.
