Browse all 5 CVE security advisories affecting phoenixframework. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-64941 | Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR — phoenix_live_view CWE-601 | 2.1 | Low | 2026-08-10 |
| CVE-2026-58228 | Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link> — phoenix_live_view CWE-79 | - | - | 2026-07-13 |
| CVE-2026-56812 | Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff — phoenix CWE-754 | 6.3 | Medium | 2026-07-07 |
| CVE-2026-56811 | Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service — phoenix CWE-770 | 8.7 | High | 2026-07-07 |
| CVE-2026-32689 | Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix — phoenix CWE-770 | 7.5 | - | 2026-05-05 |
This page lists every published CVE security advisory associated with phoenixframework. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.