StackRadar

CVE-2026-24425

High

Advisory

Published 5 Jun 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.008
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 1
affected package

Twig: Possible sandbox bypass when using a source policy

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
twig/twigcomposerv3.11.3, v3.14.0, v3.14.2, v3.21.1+1 more3.26.07
OSV records
GHSA-2q52-x2ff-qgfr

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
phpmyadminalekcVerified publisher0.3.11 of 1See more

phpmyadmin alekc 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

2,582
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

12,170
phpmyadminphpmyadminVerified publisher1.0.31 of 1See more

phpmyadmin phpmyadmin 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

2,582
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
twig/twig@v3.14.2
3.26.0

Open the chart page →

5,315
redirectwyrihaximusnetVerified publisher1.1.01 of 1See more

redirect wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/redirect:randombf5983d754d7
twig/twig@v3.14.0
3.26.0

Open the chart page →

1,581
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
twig/twig@v3.24.0
3.26.0

Open the chart page →

5,039
firefly-iii-stackfirefly-iii0.10.21 of 4See more

firefly-iii-stack firefly-iii 0.10.2

1 of the 4 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
twig/twig@v3.24.0
3.26.0

Open the chart page →

10,260
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

5,704
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

5,704
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

12,170
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
twig/twig@v3.11.3
3.26.0

Open the chart page →

4,751
wallabaghelmforgeVerified publisher1.3.61 of 3See more

wallabag helmforge 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.26.0

Open the chart page →

2,762
wallabaghpVerified publisher0.1.71 of 1See more

wallabag hp 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.26.0

Open the chart page →

1,136
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
jeboehm/mailserver-web:5.0.929da13edf5aa8
twig/twig@v3.21.1
3.26.0

Open the chart page →

10,897
wallabagsebtiz13-chartsVerified publisher0.6.01 of 1See more

wallabag sebtiz13-charts 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.26.0

Open the chart page →

1,136
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-24425.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

5,704

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/phpmyadmin:5.2.3-apache:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0
7
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.26.0
3
fireflyiii/core:version-6.5.9fe4ecec4c2ba
twig/twig@v3.24.0
3.26.0
2
ckulka/baikal:0.10.1-nginx434bdd162247
twig/twig@v3.14.2
3.26.0
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
twig/twig@v3.21.1
3.26.0
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
twig/twig@v3.11.3
3.26.0
1
ghcr.io/wyrihaximusnet/redirect:randombf5983d754d7
twig/twig@v3.14.0
3.26.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.