CVE-2026-23498
Impact
We fixed with CVE-2023-2017 Twig filters to only be executed with allowed functions. However there was a regression that lead to an array and array crafted PHP Closure not checked being against allow list for the map(...) override
Patches
Patched in 6.7.6.1
Workarounds
Install the security plugin
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/shopware/shopware/security/advisories/GHSA-7cw6-7h3h-v8pf, https://nvd.nist.gov/vuln/detail/CVE-2026-23498, https://github.com/shopware/shopware/commit/3966b05590e29432b8485ba47b4fcd14dd0b8475, https://github.com/advisories/GHSA-7v2v-9rm4-7m8f, https://github.com/shopware/shopware
