PatchSiren cyber security CVE debrief
CVE-2026-72587 CoreBunch CVE debrief
A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /_instatic/hole/<nodeId> server island endpoint. This vulnerability has a CVSS score of 6.1, indicating medium severity. Organizations should review and assess the vulnerability's impact on their assets. The CVE record was published on 2026-08-10T11:17:31.760Z and has not been modified since then. Affected product deployments should be identified and reviewed for potential exposure.
- Vendor
- CoreBunch
- Product
- Instatic
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-10
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-10
Who should care
Organizations using CoreBunch/Instatic version 0.0.14 or earlier should review and assess the vulnerability's impact on their assets. Security teams and administrators responsible for web application security should prioritize reviewing and mitigating this vulnerability. Affected operators and platforms should be identified, and vulnerability management processes should be engaged. Security teams should also monitor for potential exploitation attempts and implement compensating controls if necessary. Additionally, asset inventory and rollback/change windows should be reviewed to ensure adequate protection. This vulnerability may require immediate attention from security teams and administrators to prevent potential cache poisoning attacks. Review of the affected product scope and defensive impact is necessary to ensure proper mitigation. The CVE record was published on 2026-08-10T11:17:31.760Z and has not been modified since then, emphasizing the need for prompt action. Security teams should verify the affected product versions in their environments and plan for vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Relevant monitoring, detection, and logs should be checked for exposed assets that need extra review. Exceptions should be tracked, and remediated assets should be retested before closing the item, with evidence documented to confirm mitigation. This vulnerability's medium severity and potential impact on web application security necessitate a thorough review of affected systems and prompt implementation of defensive measures. The CVE record's publication and lack of modification emphasize the importance of addressing this vulnerability promptly. Security teams should also consider the potential operational impact of this vulnerability on their organizations and prioritize mitigation efforts accordingly. The vulnerability's details and CVSS score indicate a need for medium-priority defensive review and potential remediation to prevent cache poisoning attacks. A thorough review of the CVE record and NVD
Technical summary
A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /_instatic/hole/<nodeId> server island endpoint. The vulnerability has a CVSS score of 6.1, indicating medium severity. This issue affects web applications using CoreBunch/Instatic version 0.0.14 or earlier. Security teams should prioritize reviewing and mitigating this vulnerability. The CVE record was published on 2026-08-10T11:17:31.760Z.
Defensive priority
Medium-priority defensive review recommended due to potential cache poisoning vulnerability.
Recommended defensive actions
- Review and verify the affected product version
- Assess the vulnerability's impact on the organization's assets
- Implement compensating controls to mitigate the vulnerability
- Monitor for potential exploitation attempts
- Apply vendor remediation when available
Evidence notes
Evidence from official CVE and NVD sources indicates a cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14. The vulnerability allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /_instatic/hole/<nodeId> server island endpoint. CVSS score is 6.1, indicating medium severity.
Official resources
-
CVE-2026-72587 CVE record
CVE.org
-
CVE-2026-72587 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T11:17:31.760Z and has not been modified since then.