Exposure of Phoenix Framework
Web frameworks14
exposure score
1,098
sites use
0
exploited
0
critical
CVEs
5 resultsCVE-2026-56811HIGHPhoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of serviceEPSS 0.8%CVE-2026-58228MEDIUMScheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>EPSS 0.6%CVE-2026-56812MEDIUMPhoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiffEPSS 0.5%CVE-2026-32689HIGHLong-poll NDJSON body splitting causes unbounded memory allocation in PhoenixEPSS 0.5%CVE-2026-64941LOWOpen redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CREPSS 0.3%