Skip to content

Symfony Blog

All about Symfony releases, new Symfony features, and other important announcements

May 20, 2026 #Releases 🚀 1
Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
PHP code injection via `{% use %}` template name
Sandbox does not protect against resource exhaustion
The `spaceless` filter implicitly marks its output as safe
Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments
`template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
Sandbox property allowlist bypass via the `column` filter (array_column on objects)
HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
Arbitrary PHP code execution via `_self.(