StackRadar

CVE-2026-48806

Medium

Advisory

Published 30 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
96
of 17,781 indexed, latest versions
Container images
72
deployed by those charts
Fix available
1 of 1
affected package

Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys

Carried by container images the latest versions of 96 of 17,781 indexed charts deploy, on 72 images.

Affected packageAffected versionsFixed inImages
twig/twigcomposerv1.35.0, v1.35.3, v1.42.5, v2.5.0+17 more3.27.072
OSV records
GHSA-5v5v-ww74-355v

Charts affected

96 by stars
ChartLatestAffected imagesRadar Score
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.27.0

Open the chart page →

5,704
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
twig/twig@v3.3.8
3.27.0

Open the chart page →

8,392
wallabaggeek-cookbookVerified publisher7.2.01 of 1See more

wallabag geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
wallabag/wallabag:2.4.25e4c26a7fb4a
twig/twig@v2.14.4
3.27.0

Open the chart page →

4,358
xbackbonegeek-cookbookVerified publisher5.4.21 of 1See more

xbackbone geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
pe46dro/xbackbone-docker:3.3.309dfe3aa10f6
twig/twig@v2.13.1
3.27.0

Open the chart page →

1,655
glpiglpi-chart0.1.12 of 3See more

glpi glpi-chart 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.27.0
vdiogov/glpi-conteiner:latest6945f84f0058
twig/twig@v3.8.0
3.27.0

Open the chart page →

12,170
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,510
cachethelm-charts-nr1.3.51 of 2See more

cachet helm-charts-nr 1.3.5

1 of the 2 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
cachethq/docker:2.3.15a61ff0f67ea7
twig/twig@v1.35.3
3.27.0

Open the chart page →

1,896
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
twig/twig@v3.11.3
3.27.0

Open the chart page →

4,751
wallabaghelmforgeVerified publisher1.3.61 of 3See more

wallabag helmforge 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.27.0

Open the chart page →

2,762
wallabaghpVerified publisher0.1.71 of 1See more

wallabag hp 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.27.0

Open the chart page →

1,136
instemmingserviceinstemmingservice1.0.01 of 3See more

instemmingservice instemmingservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,510
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
twig/twig@v2.13.1
3.27.0

Open the chart page →

8,534
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,510
loggingcomponentloggingcomponent1.0.01 of 3See more

loggingcomponent loggingcomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,492
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,499
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
jeboehm/mailserver-web:5.0.929da13edf5aa8
twig/twig@v3.21.1
3.27.0

Open the chart page →

10,897
medewerkercatalogusmedewerkercatalogus1.0.01 of 3See more

medewerkercatalogus medewerkercatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
twig/twig@v3.3.10
3.27.0

Open the chart page →

7,327
memo-componentmemo-component1.0.01 of 3See more

memo-component memo-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/memo-component-php:latestef77f4c089a1
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,510
fossologymidokura-communityVerified publisher0.2.21 of 2See more

fossology midokura-community 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
fossology/fossology:4.2.18bd1f22ba7bb
twig/twig@v3.4.3
3.27.0

Open the chart page →

3,294
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,527
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
twig/twig@v3.4.3
3.27.0

Open the chart page →

9,724
orderregistratiecomponentorderregistratiecomponent1.0.01 of 3See more

orderregistratiecomponent orderregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/orderregistratiecomponent-php:latestd17257e4fa27
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,492
firefly-iiiphntom0.2.101 of 2See more

firefly-iii phntom 0.2.10

1 of the 2 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
phntom/fireflyiii:version-5.7.5f881ea5fbbf1
twig/twig@v3.3.10
3.27.0

Open the chart page →

1,813
procestypecatalogusprocestypecatalogus1.1.01 of 4See more

procestypecatalogus procestypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,429
productenendienstencatalogusproductenendienstencatalogus1.0.01 of 3See more

productenendienstencatalogus productenendienstencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,510
panproto-application-nldesign0.1.01 of 5See more

pan proto-application-nldesign 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
conduction/pan-php:dev24f03c57568f
twig/twig@v2.13.1
3.27.0

Open the chart page →

8,725
proto-component-commongroundproto-component-commonground1.0.01 of 3See more

proto-component-commonground proto-component-commonground 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,510
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,491
shopwarerobjuz2.0.01 of 6See more

shopware robjuz 2.0.0

1 of the 6 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
shyim/shopware:6.4.6.0a951c0e6b836
twig/twig@v3.3.3
3.27.0

Open the chart page →

2,972
mauticromholdings0.1.31 of 3See more

mautic romholdings 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
twig/twig@v1.35.0
3.27.0

Open the chart page →

2,939
phpmyadminsb-helm-charts0.3.01 of 1See more

phpmyadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
twig/twig@v3.5.0
3.27.0

Open the chart page →

5,315
wallabagsebtiz13-chartsVerified publisher0.6.01 of 1See more

wallabag sebtiz13-charts 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.27.0

Open the chart page →

1,136
cachetsergiotocaliniVerified publisher1.0.01 of 1See more

cachet sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
cachethq/docker:2.3.15a61ff0f67ea7
twig/twig@v1.35.3
3.27.0

Open the chart page →

1,896
phpmyadminsitepilot1.0.11 of 1See more

phpmyadmin sitepilot 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.138437e021deb
twig/twig@v2.14.13
3.27.0

Open the chart page →

1,724
commonground-gatewayskeleton-pip0.1.71 of 5See more

commonground-gateway skeleton-pip 0.1.7

1 of the 5 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
twig/twig@v3.4.3
3.27.0

Open the chart page →

2,825
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,480
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
twig/twig@v3.3.7
3.27.0

Open the chart page →

3,993
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.27.0

Open the chart page →

5,704
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,510
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
twig/twig@v2.13.1
3.27.0

Open the chart page →

7,429
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
twig/twig@v3.3.10
3.27.0

Open the chart page →

7,552
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
twig/twig@v3.3.3
3.27.0

Open the chart page →

2,534
satisfyymrs1.0.21 of 1See more

satisfy ymrs 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-48806.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
twig/twig@v2.5.0
3.27.0

Open the chart page →

1,572

Container images carrying it

72 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/phpmyadmin:5.2.3-apache:latest3a8a8d6b5289
twig/twig@v3.11.3
3.27.0
7
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
twig/twig@v3.4.3
3.27.0
5
cachethq/docker:2.3.15a61ff0f67ea7
twig/twig@v1.35.3
3.27.0
4
anapsix/satisfyfae78e3809e9
twig/twig@v2.5.0
3.27.0
3
buddy/repman:1.4.0097c897f8b54
twig/twig@v3.3.7
3.27.0
3
mautic/mautic:2.13-apachea954c5868d76
twig/twig@v1.35.0
3.27.0
3
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
twig/twig@v3.3.10
3.27.0
3
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.27.0
3
fireflyiii/core:version-6.5.9fe4ecec4c2ba
twig/twig@v3.24.0
3.27.0
2
library/phpmyadmin:5.2.16e75aa8f767c
twig/twig@v3.5.0
3.27.0
2
vdiogov/glpi-conteiner:latest6945f84f0058
twig/twig@v3.8.0
3.27.0
2
ckulka/baikal:0.10.1-nginx434bdd162247
twig/twig@v3.14.2
3.27.0
1
ckulka/baikal:0.8.0aedb1f4f3fa0
twig/twig@v2.13.1
3.27.0
1
conduction/agendaservice-php:latest9cfeeb6c7c20
twig/twig@v2.13.1
3.27.0
1
conduction/balance-registration-php:devc36094a41369
twig/twig@v2.13.1
3.27.0
1
conduction/betaalservice-php:latestece1ab544c57
twig/twig@v2.13.1
3.27.0
1
conduction/cgrc-php:dev25415534d245
twig/twig@v2.12.5
3.27.0
1
conduction/checkin-component-php:dev3423845692c1
twig/twig@v2.13.1
3.27.0
1
conduction/conduction-ui-php:dev2744565516e8
twig/twig@v2.13.1
3.27.0
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
twig/twig@v2.13.1
3.27.0
1
conduction/docparser-php:devb6f95c8ead7d
twig/twig@v2.13.1
3.27.0
1
conduction/kvk-php:dev8f177f9f8a7b
twig/twig@v2.13.1
3.27.0
1
conduction/pan-php:dev24f03c57568f
twig/twig@v2.13.1
3.27.0
1
fireflyiii/core:version-5.6.142f4283bd0cf7
twig/twig@v3.3.8
3.27.0
1
fossology/fossology:4.2.18bd1f22ba7bb
twig/twig@v3.4.3
3.27.0
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
twig/twig@v3.21.1
3.27.0
1
library/drupal:8-apache8a1a3ee83899
twig/twig@v1.42.5
3.27.0
1
mautic/mautic:v4-apache94ea4acf4049
twig/twig@v3.8.0
3.27.0
1
openemr/openemr:6.1.089eaa6d9a4e3
twig/twig@v3.3.8
3.27.0
1
pe46dro/xbackbone-docker:3.3.309dfe3aa10f6
twig/twig@v2.13.1
3.27.0
1
phntom/fireflyiii:version-5.7.5f881ea5fbbf1
twig/twig@v3.3.10
3.27.0
1
phpmyadmin/phpmyadmin:5.138437e021deb
twig/twig@v2.14.13
3.27.0
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
twig/twig@v3.11.3
3.27.0
1
shyim/shopware:6.4.6.0a951c0e6b836
twig/twig@v3.3.3
3.27.0
1
wallabag/wallabag:2.4.25e4c26a7fb4a
twig/twig@v2.14.4
3.27.0
1
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
twig/twig@v2.13.1
3.27.0
1
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
twig/twig@v2.13.1
3.27.0
1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
twig/twig@v3.3.10
3.27.0
1
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
twig/twig@v2.13.1
3.27.0
1
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
twig/twig@v3.3.10
3.27.0
1
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
twig/twig@v2.13.1
3.27.0
1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
twig/twig@v3.4.1
3.27.0
1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
twig/twig@v3.3.10
3.27.0
1
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
twig/twig@v2.13.1
3.27.0
1
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
twig/twig@v2.13.1
3.27.0
1
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
twig/twig@v2.13.1
3.27.0
1
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
twig/twig@v2.13.1
3.27.0
1
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
twig/twig@v2.13.1
3.27.0
1
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
twig/twig@v2.13.1
3.27.0
1
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
twig/twig@v3.3.10
3.27.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.