VendorsPhoenix Frameworkphoenixall versions
Vulnerabilities

Phoenix Framework Phoenix

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2026-56811
Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
Published 2026-07-07 · Modified
8.7EPSS 0.008
CVE-2026-56812
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
Published 2026-07-07 · Modified
7.5EPSS 0.008
CVE-2022-42975
socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF token.
Published 2022-10-17 · Modified
7.5EPSS 0.006
CVE-2017-1000163
The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.
Published 2017-11-17 · Modified
6.1EPSS 0.024