Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-56811— Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service

Quick assessment

Affected
phoenixframework phoenix
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

phoenixframework phoenix是phoenixframework团队开源的一款Web开发框架。 phoenixframework phoenix存在资源管理错误漏洞,该漏洞源于资源无限制分配或节流问题,可能导致未经身份验证的攻击者对挂载具有可达信道传输的Phoenix套接字的端点造成拒绝服务。以下版本受到影响:0.11.0至1.5.15之前版本、1.6.0-rc.0至1.6.17之前版本、1.7.0-rc.0至1.7.24之前版本和1.8.0-rc.0至1.8.9之前版本。

CVSS 8.7 · High EPSS 0.78% · P54

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 5

VendorProduct Version RangeStatus
phoenixframework phoenix 0.11.0< 1.5.15 affected
1.6.0-rc.0< 1.6.17 affected
1.7.0-rc.0< 1.7.24 affected
1.8.0-rc.0< 1.8.9 affected
14a297e88023cb280a577962a49a0bbdeef9f4eb< * affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-56811

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
Source: CVE Program / CVE List V5
Vulnerability Description
Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with a reachable channel transport (WebSocket or LongPoll). This vulnerability is associated with program files lib/phoenix/socket.ex and program routine 'Elixir.Phoenix.Socket':handle_in/4. Phoenix transports do not limit the number of channels that a single transport process may join. Every phx_join message a client sends over one connection starts a persistent channel process, and the socket process accepts an unbounded number of them. A single unauthenticated client can therefore open one WebSocket or LongPoll connection and stream a large number of phx_join messages, spawning hundreds of thousands of channel processes over that one connection and eventually reaching the BEAM maximum process limit. Once the process table is exhausted the virtual machine can no longer start new processes, denying service to legitimate traffic across the whole node. Because the amplification happens inside a single connection, network-layer connection caps and rate limiting do not mitigate it. The fix adds a :max_channels_per_transport option (default 100) that bounds the number of channels a single transport process can join, forcing abusive clients to open many connections instead, where external load balancers and reverse proxies can throttle them. This issue affects phoenix: from 0.11.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5
Vulnerability Title
phoenixframework phoenix 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
phoenixframework phoenix是phoenixframework团队开源的一款Web开发框架。 phoenixframework phoenix存在资源管理错误漏洞,该漏洞源于资源无限制分配或节流问题,可能导致未经身份验证的攻击者对挂载具有可达信道传输的Phoenix套接字的端点造成拒绝服务。以下版本受到影响:0.11.0至1.5.15之前版本、1.6.0-rc.0至1.6.17之前版本、1.7.0-rc.0至1.7.24之前版本和1.8.0-rc.0至1.8.9之前版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
phoenixframework phoenix 0.11.0 ~ 1.5.15 cpe:2.3:a:phoenixframework:phoenix:*:*:*:*:*:*:*:*
phoenixframework phoenix 14a297e88023cb280a577962a49a0bbdeef9f4eb ~ * cpe:2.3:a:phoenixframework:phoenix:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-56811

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56811

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-56811 (4)

Vendor Advisories for CVE-2026-56811 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-56811

No comments yet


Leave a comment