A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /_instatic/hole/<nodeId> server island endpoint.
References
| Link | Resource |
|---|---|
| https://github.com/CoreBunch/Instatic |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 11:17
Updated : 2026-08-28 18:51
NVD link : CVE-2026-72587
Mitre link : CVE-2026-72587
CVE.ORG link : CVE-2026-72587
JSON object : View
Products Affected
No product.
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
