phoenix
1.8.7
Peace of mind from prototype to production
Current section
3 Advisories
Jump to
Current section
3 Advisories
Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-32689.html
- https://github.com/phoenixframework/phoenix
- https://github.com/phoenixframework/phoenix/commit/1a67c61ff9ce0a7711662ac7354861917a7c80f7
- https://github.com/phoenixframework/phoenix/commit/912ea181fd247c21dbcc49fb97d0053b947d81bf
- https://github.com/phoenixframework/phoenix/security/advisories/GHSA-628h-q48j-jr6q
- https://hex.pm/packages/phoenix
- https://nvd.nist.gov/vuln/detail/CVE-2026-32689
- https://osv.dev/vulnerability/EEF-CVE-2026-32689
Phoenix before 1.6.14 mishandles check_origin wildcarding
Affected Versions
Phoenix Arbitrary URL Redirect
Affected Versions
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
330 427
yesterday
46 851
last 7 days
281 490
all time
150 100 697