PatchSiren cyber security CVE debrief
CVE-2026-72587 CoreBunch CVE debrief
A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /_instatic/hole/<nodeId> server island endpoint. This vulnerability has a CVSS score of 6.1, indicating medium severity. Organizations should review and assess the vulnerability's impact on their assets. The CVE record was published on 2026-08-10T11:17:31.760Z and has not been modified since then. Affected product deployments should be identified and reviewed for potential exposure.
- Vendor
- CoreBunch
- Product
- Instatic
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-28
Who should care
Organizations using CoreBunch/Instatic version 0.0.14 or earlier should review and assess the vulnerability's impact on their assets. Security teams and administrators responsible for web application security should prioritize reviewing and mitigating this vulnerability. Affected operators and platforms should be identified, and vulnerability management processes should be engaged. Security teams should also monitor for potential exploitation attempts and implement compensating controls if necessary. Additionally, asset inventory and rollback/change windows should be reviewed to ensure adequate protection. This vulnerability may require immediate attention from security teams and administrators to prevent potential cache poisoning attacks. Review of the affected product scope and defensive impact is necessary to ensure proper mitigation. The CVE record was published on 2026-08-10T11:17:31.760Z and has not been modified since then, emphasizing the need for prompt action. Security teams should verify the affected product versions in their environments and plan for vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Relevant monitoring, detection, and logs should be checked for exposed assets that need extra review. Exceptions should be tracked, and remediated assets should be retested before closing the item, with evidence documented to confirm mitigation. This vulnerability's medium severity and potential impact on web application security necessitate a thorough review of affected systems and prompt implementation of defensive measures. The CVE record's publication and lack of modification emphasize the importance of addressing this vulnerability promptly. Security teams should also consider the potential operational impact of this vulnerability on their organizations and prioritize mitigation efforts accordingly. The vulnerability's details and CVSS score indicate a need for medium-priority defensive review and potential remediation to prevent cache poisoning attacks. A thorough review of the CVE record and NVD
Technical summary
A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /_instatic/hole/<nodeId> server island endpoint. The vulnerability has a CVSS score of 6.1, indicating medium severity. This issue affects web applications using CoreBunch/Instatic version 0.0.14 or earlier. Security teams should prioritize reviewing and mitigating this vulnerability. The CVE record was published on 2026-08-10T11:17:31.760Z.
Defensive priority
Medium-priority defensive review recommended due to potential cache poisoning vulnerability.
Recommended defensive actions
- Review and verify the affected product version
- Assess the vulnerability's impact on the organization's assets
- Implement compensating controls to mitigate the vulnerability
- Monitor for potential exploitation attempts
- Apply vendor remediation when available
Evidence notes
Evidence from official CVE and NVD sources indicates a cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14. The vulnerability allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /_instatic/hole/<nodeId> server island endpoint. CVSS score is 6.1, indicating medium severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72587 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72587
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72587 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72587
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/CoreBunch/Instatic
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.