Answer in brief
CVE-2026-64941 records a Low severity (CVSS 2.1) vulnerability in Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR. The current sources do not mark it as known exploited. The current feed maps phoenixframework/phoenix_live_view (generic), phoenixframework/phoenix_live_view (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 2.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps phoenixframework/phoenix_live_view (generic), phoenixframework/phoenix_live_view (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| phoenixframework/phoenix_live_viewgeneric | >=0.5.0 <1.0.19 || >=1.1.0-rc.0 <1.1.33 || >=1.2.0-rc.0 <1.2.9 | 1.0.19, 1.1.33, 1.2.9 |
| phoenixframework/phoenix_live_viewgeneric | >=b20dba3f65a380b2e4868dae03397f13d2daa070 <* | * |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attacker to send a victim's browser to an origin of the attacker's choosing via a :to value containing ASCII tab, LF or CR. redirect/2 validates :to through the private validate_local_url!/2 in lib/phoenix_live_view.ex, which is intended to guarantee the target is a path within the application. It rejects a leading // and any backslash, but not ASCII tab, LF or CR. Browsers strip those three characters before parsing a URL, so a value such as /<TAB>/example.com passes validation as a path and is then resolved as the scheme-relative URL //example.com. The live navigation functions share the guard but are not affected, because the client expands their target against the current origin. push_patch/2 is also affected before 0.7.0, which is when that expansion was added. This issue affects phoenix_live_view: from 0.5.0 before 1.0.19, from 1.1.0-rc.0 before 1.1.33, and from 1.2.0-rc.0 before 1.2.9.
Quoted source text, attributed separately from HOL analysis.