PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-56812 phoenixframework CVE debrief

CVE-2026-56812 is an Improper Check for Unusual or Exceptional Conditions vulnerability in the Phoenix JavaScript presence client. An attacker with ordinary channel access can cause a persistent client-side denial of service against every viewer of a presence channel topic. The vulnerability is due to a bare truthiness test (state[key]) instead of an own-property check, allowing an attacker to control presence keys and cause an uncaught TypeError. This issue affects phoenix framework versions from 1.2.0-rc.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9.

Vendor
phoenixframework
Product
phoenix
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-07
Original CVE updated
2026-09-24
Advisory published
2026-07-07
Advisory updated
2026-09-24

Who should care

Users of phoenix framework, particularly those using versions from 1.2.0-rc.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9, should be aware of this vulnerability and take necessary actions to mitigate it.

Technical summary

The Phoenix JavaScript presence client checks for presence using a bare truthiness test (state[key]) instead of an own-property check. This allows an attacker to control presence keys and cause an uncaught TypeError by choosing a key that is an Object.prototype member name. The exception propagates out of the presence message handler, preventing local state updates and onSync() from firing. The malicious key is tracked on the server and re-pushed on every presence update, keeping presence sync broken for every viewer of that channel topic until the attacker leaves.

Defensive priority

Medium priority due to the CVSS score of 6.3 and the potential for denial of service attacks.

Recommended defensive actions

  • Update phoenix to a version that fixes the vulnerability (1.5.15, 1.6.17, 1.7.24, or 1.8.9)
  • Implement own-property checks for presence keys
  • Monitor presence channel topics for suspicious activity
  • Consider using compensating controls such as rate limiting or IP blocking
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record was published on 2026-07-07T16:16:40.920Z and has not been modified since then. The NVD entry is currently Received. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the vendor. The vulnerability affects phoenix framework versions from 1.2.0-rc.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-56812 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-56812

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-56812 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-56812

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cna.erlef.org/cves/CVE-2026-56812.html

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/phoenixframework/phoenix/commit/7f7b971c1ea0994e3fbd1c11ddb05e780bd38ad8

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/phoenixframework/phoenix/commit/89a1c4be161e436241e12b2378a719904b9bd96f

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/phoenixframework/phoenix/commit/b90b22521465ece00eb5a19d5aa2b9465b209c85

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/phoenixframework/phoenix/commit/beffc4da1e787e572121f68902c63daf4fe7d9c2

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/phoenixframework/phoenix/security/advisories/GHSA-63mc-hw7g-86rr

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://osv.dev/vulnerability/EEF-CVE-2026-56812

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.