← volver
CVE-2026-72587mediumCWE-444

Instatic - Cache Poisoning via Unauthenticated Server Island Endpoint

10Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 6.1
probabilidad de explotación
explotación observada
noninguna fuente lo reporta
A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /_instatic/hole/<nodeId> server island endpoint.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Productos afectados
CoreBunch · Instatic