phoenix is vulnerable to Denial of Service
87
High Risk
Affected versions of this package contain an unauthenticated denial-of-service vulnerability in the LongPoll transport. The application/x-ndjson POST handling allows a remote attacker to trigger excessive memory allocation with crafted requests. Because only a session token is required—and can be obtained via a simple GET request—this can be exploited without authentication.
You are affected if you are using a version that falls within the vulnerable range.
phoenix is vulnerable to Denial of Service in versions 1.7.0 - 1.7.21 and 1.8.0 - 1.8.5.
Upgrade the phoenix library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant