ugh, composer.
There are 16 composer security advisories affecting our repositories.
Deserialization Gadget chain in Swift Mailer
Possible sandbox bypass when using a source policy
Sandbox does not protect against resource exhaustion
The `spaceless` filter implicitly marks its output as safe
PHP code injection via `{% use %}` template name
`template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
Sandbox property allowlist bypass via the `column` filter (array_column on objects)
Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders
`{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
XSS in profiler HtmlDumper via unescaped template and profile names
Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
Sandbox `__toString()` policy bypass via dynamic mapping keys
Sandbox `__toString()` policy bypass via `Traversable` in `join`/`replace` and `in`/`not in` operators
Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
CVE-2026-45073: SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix