Phoenix Framework is a web application framework for the Elixir programming language, with a vulnerability profile that concentrates in its core components—the framework proper and its HTML templating layer—around input-handling and authorization issues, particularly cross-site scripting, improper authorization, and open-redirect weaknesses that are typical of server-side web application frameworks. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phoenixframework over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56811HIGH Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of servi | Jul 7, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-56812HIGH Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause | Jul 7, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-32689HIGH Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix allows a denial of service via the long-poll transport's NDJSON body handling.
In 'E | May 5, 2026 | 8.7 | 30 | NO | NO |
CVE-2017-1000163MEDIUM The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or | Nov 17, 2017 | 6.1 | 29 | NO | YES |
CVE-2022-42975HIGH socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF t | Oct 17, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-46871MEDIUM tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes. | Jan 10, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phoenixframework.
Media articles that mention a CVE ID that affects a product developed by Phoenixframework — matched by CVE ID, not by vendor name.