CVE-2026-56811: Unbounded Channel Joins in Phoenix Transports Enable Denial of Service
A vulnerability in Phoenix transports allows an unauthenticated remote attacker to cause a denial of service against any Phoenix app that exposes LongPoll/WebSocket transports. The vulnerability has a CVSS score of 8.7 and affects multiple versions of the Phoenix framework. To mitigate, users should update to patched versions and consider applying rate limits and other security measures.