目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-56811— phoenixframework phoenix 资源管理错误漏洞

一分钟漏洞结论

影响对象
phoenixframework phoenix
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

phoenixframework phoenix是phoenixframework团队开源的一款Web开发框架。 phoenixframework phoenix存在资源管理错误漏洞,该漏洞源于资源无限制分配或节流问题,可能导致未经身份验证的攻击者对挂载具有可达信道传输的Phoenix套接字的端点造成拒绝服务。以下版本受到影响:0.11.0至1.5.15之前版本、1.6.0-rc.0至1.6.17之前版本、1.7.0-rc.0至1.7.24之前版本和1.8.0-rc.0至1.8.9之前版本。

CVSS 8.7 · High EPSS 0.78% · P54

可能的 ATT&CK 技术 1 AI

T1499 · Endpoint Denial of Service

影响版本矩阵 5

厂商产品 版本范围状态
phoenixframework phoenix 0.11.0< 1.5.15 affected
1.6.0-rc.0< 1.6.17 affected
1.7.0-rc.0< 1.7.24 affected
1.8.0-rc.0< 1.8.9 affected
14a297e88023cb280a577962a49a0bbdeef9f4eb< * affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-56811 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
来源: CVE Program / CVE List V5
Vulnerability Description
Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with a reachable channel transport (WebSocket or LongPoll). This vulnerability is associated with program files lib/phoenix/socket.ex and program routine 'Elixir.Phoenix.Socket':handle_in/4. Phoenix transports do not limit the number of channels that a single transport process may join. Every phx_join message a client sends over one connection starts a persistent channel process, and the socket process accepts an unbounded number of them. A single unauthenticated client can therefore open one WebSocket or LongPoll connection and stream a large number of phx_join messages, spawning hundreds of thousands of channel processes over that one connection and eventually reaching the BEAM maximum process limit. Once the process table is exhausted the virtual machine can no longer start new processes, denying service to legitimate traffic across the whole node. Because the amplification happens inside a single connection, network-layer connection caps and rate limiting do not mitigate it. The fix adds a :max_channels_per_transport option (default 100) that bounds the number of channels a single transport process can join, forcing abusive clients to open many connections instead, where external load balancers and reverse proxies can throttle them. This issue affects phoenix: from 0.11.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
来源: CVE Program / CVE List V5
Vulnerability Title
phoenixframework phoenix 资源管理错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
phoenixframework phoenix是phoenixframework团队开源的一款Web开发框架。 phoenixframework phoenix存在资源管理错误漏洞,该漏洞源于资源无限制分配或节流问题,可能导致未经身份验证的攻击者对挂载具有可达信道传输的Phoenix套接字的端点造成拒绝服务。以下版本受到影响:0.11.0至1.5.15之前版本、1.6.0-rc.0至1.6.17之前版本、1.7.0-rc.0至1.7.24之前版本和1.8.0-rc.0至1.8.9之前版本。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
phoenixframework phoenix 0.11.0 ~ 1.5.15 cpe:2.3:a:phoenixframework:phoenix:*:*:*:*:*:*:*:*
phoenixframework phoenix 14a297e88023cb280a577962a49a0bbdeef9f4eb ~ * cpe:2.3:a:phoenixframework:phoenix:*:*:*:*:*:*:*:*

二、漏洞 CVE-2026-56811 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-56811 的情报信息

请登录查看更多情报信息。

CVE-2026-56811 补丁与修复 (4)

CVE-2026-56811 厂商安全公告 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-56811

暂无评论


发表评论