UNKNOWNhex →
Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
Affected packages
- phoenix
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/phoenixframework/phoenix/security/advisories/GHSA-6983-jfq8-485w
- https://cna.erlef.org/cves/CVE-2026-56811.html
- https://github.com/phoenixframework/phoenix/commit/c498ba8cf49f6accbbd0c643a5340b58db891218
- https://github.com/phoenixframework/phoenix/commit/d19ca0a8d9f82c130b7ed339b9f033433e2dea5e
- https://github.com/phoenixframework/phoenix/commit/a612100cd8a4279091abc1a2ef8fb98a6d01c0a1
- https://github.com/phoenixframework/phoenix/commit/16e295d2fccab185d1292322e2bee5d46c725c8a
- https://hex.pm/packages/phoenix
Structured record: https://osv.dev/vulnerability/EEF-CVE-2026-56811
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta