CVE-2026-23498: Shopware Has Improper Control of Generation of Code in Twig rendered views
We fixed with CVE-2023-2017 Twig filters to only be executed with allowed functions. However there was a regression that lead to an array and array crafted PHP Closure not checked being against allow list for the map(…) override
References
Code Behaviors & Features
Detect and mitigate CVE-2026-23498 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →