phoenix
Hex5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting phoenixpage 1 of 1
- CVE-2017-1000163MEDIUMCVSS 6.1EG 6.1fixed in 1.0.6, 1.1.8 or 1.2.3, by version range2017-11-17
vulnerable: 1.2.0, 1.2.1, 1.2.2
The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.
- CVE-2022-42975HIGHCVSS 7.5EG 7.5fixed in 1.6.142022-10-17
vulnerable: 0.1.0 ... 1.6.9 (128 versions)
socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF token.
- CVE-2026-32689HIGHCVSS 8.7EG 8.7fixed in 1.7.22 or 1.8.6, by version range2026-05-05
vulnerable: 1.8.0 ... 1.8.5 (6 versions)
Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix allows a denial of service via the long-poll transport's NDJSON body handling. In 'Elixir.Phoenix.Transports.LongPoll':publish/4, when a POST r…
- CVE-2026-56811HIGHCVSS 7.5EG 7.5fixed in 1.5.15, 1.6.17, 1.7.24 or 1.8.9, by version range2026-07-07
vulnerable: 1.8.0 ... 1.8.8 (14 versions)
Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with a…
- CVE-2026-56812HIGHCVSS 7.5EG 7.5fixed in 1.5.15, 1.6.17, 1.7.24 or 1.8.9, by version range2026-07-07
vulnerable: 1.8.0 ... 1.8.8 (14 versions)
Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every v…
Check whether phoenix is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for phoenix CVEs against the assets you own.
Book a Demo →