Junglewise Threat Intelligence

CVE-2026-56812: Phoenix Framework DoS in Presence JavaScript client

CVE-2026-56812 · Severity: medium · CVSS 4 · Published 2026-07-07

Executive brief

Phoenix is a popular web framework for Elixir that includes a JavaScript library for tracking user presence in real-time channels. An authenticated attacker can join a presence channel and select a username matching a built-in JavaScript object property (such as `__proto__` or `constructor`). This causes all viewers of that channel to receive malformed presence updates, triggering an uncaught error that breaks presence synchronization for every connected user until the attacker leaves.

Technical details

The vulnerability is a prototype member collision in the presence state synchronization logic. The `Presence.syncState()` and `Presence.syncDiff()` methods in `assets/js/phoenix/presence.js` use a bare `state[key]` truthiness check to determine if a presence already exists locally. When `state` is a plain JavaScript object inheriting from `Object.prototype`, accessing `state["__proto__"]` returns the truthy `Object.prototype` object rather than `undefined`. The code then attempts `currentPresence.metas.map(m => m.phx_ref)`, which fails with a `TypeError` because `Object.prototype.metas` is `undefined`. Phoenix's channel callbacks lack try/catch wrapping, so the error propagates uncaught, preventing state updates and blocking `onSync()` callbacks. The malicious key is re-pushed on every server presence update, keeping the error active until the attacker leaves. The fix uses `Object.create(null)` to create state objects without prototype chains, or employs `Object.prototype.hasOwnProperty.call()` for existence checks. The impact is scoped per channel topic and does not mutate `Object.prototype` across channels. Affected applications must pass client-controlled keys to `Presence.track()` to be vulnerable.

Affected products

  • Phoenix phoenix >= 1.2.0-rc.0, < 1.5.15; >= 1.6.0-rc.0, < 1.6.17; >= 1.7.0-rc.0, < 1.7.24; >= 1.8.0-rc.0, < 1.8.9
  • Phoenix phoenix (npm) >= 1.2.0-rc.0, < 1.5.15; >= 1.6.0-rc.0, < 1.6.17; >= 1.7.0-rc.0, < 1.7.24; >= 1.8.0-rc.0, < 1.8.9

Timeline

  • 2026-07-07: disclosed: Published to NVD
  • 2026-09-03: advisory: Published to GitHub Advisory Database and reviewed
  • 2026-09-03: patched: Patched versions available: 1.5.15, 1.6.17, 1.7.24, 1.8.9

References

Related threats