Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 24 SEP 2026

Phoenix Framework Project · AUTOMATIC DISCOVERY

Phoenix Framework Lifecycle policy

Phoenix Framework is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 82. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

This discovery does not establish a product-specific support or retirement date. A missing date does not mean support continues.

Product overview

Phoenix Framework is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductPhoenix Framework
ReleaseLifecycle policy
Start or releaseNot extracted
Lifecycle boundaryContinuous or not dated in the source
Date precisionUnknown

Known exploited vulnerabilities

Catalogue updated 1 Oct 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

No CISA known-exploited entries currently match this mapped product family.

This does not mean the product has no vulnerabilities.

Package vulnerability advisories

Checked 27 Sep 2026

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

CVE-2026-56811High severity

Phoenix: Unbounded channel joins per transport enables DoS over few connections

pkg:hex/phoenixFixed: 1.5.15, 1.6.17, 1.7.24, 1.8.9

OSV record
CVE-2026-32689High severity

Phoenix: Long-poll NDJSON body splitting causes large memory allocation

pkg:hex/phoenixFixed: 1.7.22, 1.8.6

OSV record
CVE-2026-56812Medium severity

Phoenix: Presence keys colliding with `Object.prototype` members break existence checks

pkg:hex/phoenixFixed: 1.5.15, 1.6.17, 1.7.24, 1.8.9

OSV record
CVE-2026-56812Unknown severity

Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff

pkg:hex/phoenixFixed: 1.5.15, 1.6.17, 1.7.24, 1.8.9, 7f7b971c1ea0994e3fbd1c11ddb05e780bd38ad8, 89a1c4be161e436241e12b2378a719904b9bd96f, b90b22521465ece00eb5a19d5aa2b9465b209c85, beffc4da1e787e572121f68902c63daf4fe7d9c2

OSV record
CVE-2026-56811Unknown severity

Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service

pkg:hex/phoenixFixed: 1.5.15, 1.6.17, 1.7.24, 1.8.9, c498ba8cf49f6accbbd0c643a5340b58db891218, d19ca0a8d9f82c130b7ed339b9f033433e2dea5e, a612100cd8a4279091abc1a2ef8fb98a6d01c0a1, 16e295d2fccab185d1292322e2bee5d46c725c8a

OSV record
CVE-2026-32689Unknown severity

Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix

pkg:hex/phoenixFixed: 1.7.22, 1.8.6, 1a67c61ff9ce0a7711662ac7354861917a7c80f7, 912ea181fd247c21dbcc49fb97d0053b947d81bf

OSV record

Source evidence

PRIMARYManual

Phoenix Framework official lifecycle source

SECURITY.md | Security Policy | Supported versions | Phoenix applies bug fixes only to the latest minor branch. Security patches are available for the last 4 minor branches: | Announcements

Publisher identity used by product-specific official-source collectors.

First collected 12 Sep 2026 · Last collected 24 Sep 2026 · Review state accepted

Open official vendor source