Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-56812— Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff

Quick assessment

Affected
phoenixframework phoenix
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

phoenixframework phoenix是phoenixframework团队开源的一款Web开发框架。 phoenixframework phoenix 1.2.0-rc.0版本至1.5.15之前版本、1.6.0-rc.0版本至1.6.17之前版本、1.7.0-rc.0版本至1.7.24之前版本和1.8.0-rc.0版本至1.8.9之前版本存在异常处理不当漏洞,该漏洞源于对程序文件assets/js/phoenix/presence.js以及程序例程Presence.syncState和Pres

CVSS 6.3 · Medium EPSS 0.80% · P55

Possible ATT&CK Techniques 1 AI

T1429

Affected Version Matrix 9

VendorProduct Version RangeStatus
phoenixframework phoenix 1.2.0-rc.0< 1.5.15 affected
1.6.0-rc.0< 1.6.17 affected
1.7.0-rc.0< 1.7.24 affected
1.8.0-rc.0< 1.8.9 affected
1.2.0-rc.0< 1.5.15 affected
1.6.0-rc.0< 1.6.17 affected
1.7.0-rc.0< 1.7.24 affected
1.8.0-rc.0< 1.8.9 affected
… +1 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-56812

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every viewer of a presence channel topic. This vulnerability is associated with program files assets/js/phoenix/presence.js and program routines Presence.syncState and Presence.syncDiff. The Phoenix JavaScript presence client checks whether a presence already exists with a bare truthiness test (state[key]) instead of an own-property check. Presence keys can be attacker-controlled, because applications track presences under a username or id supplied by the client. A user who joins a channel choosing a key that is an Object.prototype member name (__proto__, constructor, toString, hasOwnProperty, and similar) makes that lookup return JavaScript's built-in Object.prototype instead of undefined. Because the prototype is truthy, the code treats it as an existing presence and reads .metas.map(...) off it, which throws an uncaught TypeError. The exception propagates out of the presence message handler, so the local state is never updated and onSync() never fires. Because the malicious key is tracked on the server, it is re-pushed on every presence update and keeps re-throwing, so presence sync stays broken for every viewer of that channel topic until the attacker leaves. Both syncState and syncDiff use the same unsafe existence-check pattern. The impact is limited to the affected topic and is a read-time confusion of the prototype object, not a mutation of Object.prototype (it is not prototype pollution). This issue affects phoenix: from 1.2.0-rc.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9; phoenix: from 1.2.0-rc.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对因果或异常条件的不恰当检查
Source: CVE Program / CVE List V5
Vulnerability Title
phoenixframework phoenix 异常处理不当漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
phoenixframework phoenix是phoenixframework团队开源的一款Web开发框架。 phoenixframework phoenix 1.2.0-rc.0版本至1.5.15之前版本、1.6.0-rc.0版本至1.6.17之前版本、1.7.0-rc.0版本至1.7.24之前版本和1.8.0-rc.0版本至1.8.9之前版本存在异常处理不当漏洞,该漏洞源于对程序文件assets/js/phoenix/presence.js以及程序例程Presence.syncState和Pres
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
phoenixframework phoenix 1.2.0-rc.0 ~ 1.5.15 cpe:2.3:a:phoenixframework:phoenix:*:*:*:*:*:*:*:*
phoenixframework phoenix 1.2.0-rc.0 ~ 1.5.15 cpe:2.3:a:phoenixframework:phoenix:*:*:*:*:*:*:*:*
phoenixframework phoenix 2270aaf21bd02c6a6a1022820564efb605a97655 ~ * cpe:2.3:a:phoenixframework:phoenix:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-56812

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56812

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-56812 (4)

Vendor Advisories for CVE-2026-56812 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-56812

No comments yet


Leave a comment