twig/twig is vulnerable to Uncontrolled Recursion
21
Low Risk
Affected versions of this package are vulnerable to denial-of-service (DoS) attacks due to inadequate recursion limit enforcement. A regression introduced after a fix in version 3.14.1 allows crafted input to trigger excessive recursive calls, potentially leading to stack exhaustion. This flaw can be exploited by attackers to crash the application or render it unresponsive, disrupting service availability. It is recommended to update to a patched version to mitigate this issue.
You are affected if you are using a version that falls within the vulnerable range.
twig/twig is vulnerable to Uncontrolled Recursion in versions 3.14.1 - 3.14.1.
Upgrade the twig/twig library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant