Intel

AIKIDO-2026-10750

phoenix is vulnerable to Denial of Service

Denial of ServiceCVE-2026-32689

87

High Risk

This Affects:

ELIXIRphoenix
1.7.0 - 1.7.21
Fixed in 1.7.22
1.8.0 - 1.8.5
Fixed in 1.8.6
Are you affected? Scan for Free

TL;DR

Affected versions of this package contain an unauthenticated denial-of-service vulnerability in the LongPoll transport. The application/x-ndjson POST handling allows a remote attacker to trigger excessive memory allocation with crafted requests. Because only a session token is required—and can be obtained via a simple GET request—this can be exploited without authentication.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

phoenix is vulnerable to Denial of Service in versions 1.7.0 - 1.7.21 and 1.8.0 - 1.8.5.

How to fix this

Upgrade the phoenix library to the patch version.