UNKNOWNhex →
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
Affected packages
- phoenix
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.51%
- EPSS percentile
- 40.5%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 41%.
Sources
- https://github.com/phoenixframework/phoenix/security/advisories/GHSA-63mc-hw7g-86rr
- https://cna.erlef.org/cves/CVE-2026-56812.html
- https://github.com/phoenixframework/phoenix/commit/7f7b971c1ea0994e3fbd1c11ddb05e780bd38ad8
- https://github.com/phoenixframework/phoenix/commit/89a1c4be161e436241e12b2378a719904b9bd96f
- https://github.com/phoenixframework/phoenix/commit/b90b22521465ece00eb5a19d5aa2b9465b209c85
- https://github.com/phoenixframework/phoenix/commit/beffc4da1e787e572121f68902c63daf4fe7d9c2
- https://hex.pm/packages/phoenix
- https://www.npmjs.com/package/phoenix
Structured record: https://osv.dev/vulnerability/EEF-CVE-2026-56812
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta