StackRadar

CVE-2026-46634

Medium

Advisory

Published 21 May 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 1
affected package

Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
twig/twigcomposerv3.11.3, v3.14.0, v3.14.2, v3.21.1+1 more3.26.07
OSV records
GHSA-24x9-r6q4-q93w

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
phpmyadminalekcVerified publisher0.3.11 of 1See more

phpmyadmin alekc 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

2,582
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

12,170
phpmyadminphpmyadminVerified publisher1.0.31 of 1See more

phpmyadmin phpmyadmin 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

2,582
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
twig/twig@v3.14.2
3.26.0

Open the chart page →

5,315
redirectwyrihaximusnetVerified publisher1.1.01 of 1See more

redirect wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/redirect:randombf5983d754d7
twig/twig@v3.14.0
3.26.0

Open the chart page →

1,581
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
twig/twig@v3.24.0
3.26.0

Open the chart page →

5,039
firefly-iii-stackfirefly-iii0.10.21 of 4See more

firefly-iii-stack firefly-iii 0.10.2

1 of the 4 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
twig/twig@v3.24.0
3.26.0

Open the chart page →

10,260
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

5,704
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

5,704
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

12,170
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
twig/twig@v3.11.3
3.26.0

Open the chart page →

4,751
wallabaghelmforgeVerified publisher1.3.61 of 3See more

wallabag helmforge 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.26.0

Open the chart page →

2,762
wallabaghpVerified publisher0.1.71 of 1See more

wallabag hp 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.26.0

Open the chart page →

1,136
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
jeboehm/mailserver-web:5.0.929da13edf5aa8
twig/twig@v3.21.1
3.26.0

Open the chart page →

10,897
wallabagsebtiz13-chartsVerified publisher0.6.01 of 1See more

wallabag sebtiz13-charts 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.26.0

Open the chart page →

1,136
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-46634.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

5,704

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/phpmyadmin:5.2.3-apache:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0
7
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.26.0
3
fireflyiii/core:version-6.5.9fe4ecec4c2ba
twig/twig@v3.24.0
3.26.0
2
ckulka/baikal:0.10.1-nginx434bdd162247
twig/twig@v3.14.2
3.26.0
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
twig/twig@v3.21.1
3.26.0
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
twig/twig@v3.11.3
3.26.0
1
ghcr.io/wyrihaximusnet/redirect:randombf5983d754d7
twig/twig@v3.14.0
3.26.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.