๐Ÿ” CVE Alert

CVE-2026-72587

MEDIUM 6.1

Instatic - Cache Poisoning via Unauthenticated Server Island Endpoint

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /_instatic/hole/<nodeId> server island endpoint.

CWE CWE-444
Vendor corebunch
Product instatic
Published Aug 10, 2026
Last Updated Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for corebunch instatic

Be the first to know when new medium vulnerabilities affecting corebunch instatic are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

CoreBunch / Instatic
0 โ‰ค 0.0.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/CoreBunch/Instatic

Credits

Komiljon Ayubov