NPM · JULY 2026 · EARLY WARNING

Potential Phoenix Framework Presence Client Vulnerability

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-56812Severity: HIGH

An early warning has been issued regarding a potential vulnerability in the Phoenix Framework's Presence JavaScript client. This vulnerability, reportedly affecting versions <1.5.15, <1.6.17, <1.7.24, and <1.8.9, may allow an attacker with ordinary channel access to cause a persistent client-side denial of service against every viewer of a presence channel topic.

What happened

The issue reportedly arises from presence keys colliding with JavaScript Object.prototype member names, leading to crashes in the Presence.syncState/syncDiff functions. This improper check for unusual or exceptional conditions is under investigation.

To assess your exposure, verify if your project utilizes the affected versions of the Phoenix Framework's Presence JavaScript client. If so, it is recommended to reject or sanitize presence keys that may collide with Object.prototype member names.

For more detailed information, consult the primary sources. The severity of this potential vulnerability is high, and further updates will be provided as more information becomes available.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If phoenixframework phoenix is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats