Intel

AIKIDO-2024-10527

twig/twig is vulnerable to Uncontrolled Recursion

Uncontrolled Recursion Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 10, 2024

21

Low Risk

This Affects:

phptwig/twig
3.14.1 - 3.14.1
Fixed in 3.14.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to denial-of-service (DoS) attacks due to inadequate recursion limit enforcement. A regression introduced after a fix in version 3.14.1 allows crafted input to trigger excessive recursive calls, potentially leading to stack exhaustion. This flaw can be exploited by attackers to crash the application or render it unresponsive, disrupting service availability. It is recommended to update to a patched version to mitigate this issue.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

twig/twig is vulnerable to Uncontrolled Recursion in versions 3.14.1 - 3.14.1.

How to fix this

Upgrade the twig/twig library to the patch version.