{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aphoenixframeworkphoenix/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:phoenixframework:phoenix:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-56811"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Phoenix (\u003e= 0.11.0, \u003c 1.5.15)","Phoenix (\u003e= 1.6.0-rc.0, \u003c 1.6.17)","Phoenix (\u003e= 1.7.0-rc.0, \u003c 1.7.24)","Phoenix (\u003e= 1.8.0-rc.0, \u003c 1.8.9)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","web-framework","cve-2026-56811"],"_cs_type":"advisory","_cs_vendors":["Phoenix"],"content_html":"\u003cp\u003eThe Phoenix web framework is vulnerable to a denial of service (DoS) condition due to an unbounded number of concurrent channel joins allowed over a single transport connection (LongPoll or WebSocket). By initiating a single connection, an unauthenticated remote attacker can programmatically trigger the creation of hundreds of thousands of Erlang processes. This behavior rapidly consumes system resources, eventually exceeding the Erlang VM's maximum process limit and resulting in a service crash. The issue, tracked as CVE-2026-56811, affects various versions across the 1.5, 1.6, 1.7, and 1.8 release branches. Defenders should note that because the exhaustion occurs within the application transport layer, standard infrastructure rate limiting may be ineffective unless applied at the connection level rather than the channel level.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a complete denial of service for any Phoenix-based application exposing LongPoll or WebSocket transports. As this does not require authentication, any internet-facing Phoenix instance is susceptible to resource exhaustion, potentially impacting critical production systems and causing significant downtime until the service is manually restarted or mitigated via patching.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch Phoenix immediately to the corrected versions: v1.5.15, v1.6.17, v1.7.24, or v1.8.9.\u003c/li\u003e\n\u003cli\u003eImplement aggressive rate limiting on connection establishment at the load balancer or reverse proxy level to mitigate the impact of rapid connection cycles.\u003c/li\u003e\n\u003cli\u003eMonitor Erlang VM metrics, specifically process counts and memory usage, for anomalous spikes that do not correlate with legitimate user traffic volume.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-04T00:05:32Z","date_published":"2026-09-04T00:05:32Z","id":"https://feed.craftedsignal.io/briefs/2026-09-phoenix-dos/","summary":"The Phoenix web framework lacks limits on channels per transport, allowing an unauthenticated attacker to cause a DoS by exhausting Erlang VM process limits via CVE-2026-56811.","title":"Phoenix Transport Channel Exhaustion Denial of Service","url":"https://feed.craftedsignal.io/briefs/2026-09-phoenix-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:phoenixframework:phoenix:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}