<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Phoenix Framework</title>
  <link>https://cvedaily.com/pages/tags/phoenix-framework.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/phoenix-framework.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Phoenix Framework</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:52 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-32689 – Allocation of Resources Without Limits or Throttling vulnerability in phoenixfra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32689</guid>
    <pubDate>Tue, 05 May 2026 16:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32689</strong></p>
  <p>Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix allows a denial of service via the long-poll transport's NDJSON body handling.  In 'Elixir.Phoenix.Transports.LongPoll':publish/4, when a POST request is received with Content-Type: application/x-ndjson, the request body is split on newline characters using String.split/2 with no limit on the number of…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-1000163 – The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000163</guid>
    <pubDate>Fri, 17 Nov 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-1000163</strong></p>
  <p>The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000163">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
