Skip to content

Symfony Blog

All about Symfony releases, new Symfony features, and other important announcements

`template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
Arbitrary PHP code execution via `_self.(
`{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
Possible sandbox bypass when using a source policy
May 20, 2026 #Releases ❤️ 3 🚀 1
May 20, 2026 #Releases ❤️ 2 👍 2
May 20, 2026 #Releases ❤️ 1
May 20, 2026 #Releases ❤️ 1
Twig 3.26.0 released
May 20, 2026 #Releases #Security Advisories #Twig ❤️ 2 🚀 3
Learn with Arnaud Oltra where to start without breaking everything. An honest retrospective full of real-world constraints, false good ideas, and practical migration tips! 🙌
May 19, 2026 #Conferences