PatchSiren cyber security CVE debrief
CVE-2026-56812 phoenixframework CVE debrief
CVE-2026-56812 is an Improper Check for Unusual or Exceptional Conditions vulnerability in the Phoenix JavaScript presence client. An attacker with ordinary channel access can cause a persistent client-side denial of service against every viewer of a presence channel topic. The vulnerability is due to a bare truthiness test (state[key]) instead of an own-property check, allowing an attacker to control presence keys and cause an uncaught TypeError. This issue affects phoenix framework versions from 1.2.0-rc.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9.
- Vendor
- phoenixframework
- Product
- phoenix
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-07
- Original CVE updated
- 2026-09-24
- Advisory published
- 2026-07-07
- Advisory updated
- 2026-09-24
Who should care
Users of phoenix framework, particularly those using versions from 1.2.0-rc.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9, should be aware of this vulnerability and take necessary actions to mitigate it.
Technical summary
The Phoenix JavaScript presence client checks for presence using a bare truthiness test (state[key]) instead of an own-property check. This allows an attacker to control presence keys and cause an uncaught TypeError by choosing a key that is an Object.prototype member name. The exception propagates out of the presence message handler, preventing local state updates and onSync() from firing. The malicious key is tracked on the server and re-pushed on every presence update, keeping presence sync broken for every viewer of that channel topic until the attacker leaves.
Defensive priority
Medium priority due to the CVSS score of 6.3 and the potential for denial of service attacks.
Recommended defensive actions
- Update phoenix to a version that fixes the vulnerability (1.5.15, 1.6.17, 1.7.24, or 1.8.9)
- Implement own-property checks for presence keys
- Monitor presence channel topics for suspicious activity
- Consider using compensating controls such as rate limiting or IP blocking
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record was published on 2026-07-07T16:16:40.920Z and has not been modified since then. The NVD entry is currently Received. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the vendor. The vulnerability affects phoenix framework versions from 1.2.0-rc.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-56812 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-56812
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-56812 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-56812
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cna.erlef.org/cves/CVE-2026-56812.html
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/phoenixframework/phoenix/commit/7f7b971c1ea0994e3fbd1c11ddb05e780bd38ad8
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/phoenixframework/phoenix/commit/89a1c4be161e436241e12b2378a719904b9bd96f
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/phoenixframework/phoenix/commit/b90b22521465ece00eb5a19d5aa2b9465b209c85
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/phoenixframework/phoenix/commit/beffc4da1e787e572121f68902c63daf4fe7d9c2
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/phoenixframework/phoenix/security/advisories/GHSA-63mc-hw7g-86rr
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://osv.dev/vulnerability/EEF-CVE-2026-56812
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.