CVE-2026-72587: Instatic - Cache Poisoning via Unauthenticated Server Island Endpoint
A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /instatic/hole/<nodeId> server island endpoint. The originating-page URL supplied in u seeds the route template frame used for rendering, and the result is stored in a shared cache keyed only on nodeId, enabling an attacker to inject a crafted route that causes all subsequent visitors to receive malformed or attacker-controlled fragment content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72587?
The severity of CVE-2026-72587 is medium with a score of 6.1.
How do I fix CVE-2026-72587?
To fix CVE-2026-72587, update CoreBunch/Instatic to the latest version that addresses this vulnerability.
What impact does CVE-2026-72587 have on my system?
CVE-2026-72587 allows an unauthenticated remote attacker to poison the shared render cache, potentially affecting the integrity of cached content.
What software is affected by CVE-2026-72587?
CVE-2026-72587 affects versions of CoreBunch/Instatic prior to 0.0.14.
When was CVE-2026-72587 published?
CVE-2026-72587 was published on August 10, 2026.