Impact
A cache poisoning vulnerability in CoreBunch Instatic versions up to 0.0.14 permits an unauthenticated remote attacker to poison the shared process‑wide render cache by manipulating the u query parameter of the GET /_instatic/hole/<nodeId> endpoint. The attacker can craft a malicious origin page URL in u, causing the server to render an attacker‑controlled route and store it in a shared cache keyed solely by nodeId. Subsequent requests to that nodeId will retrieve the attacker’s rendered fragment, achieving content poisoning.
Affected Systems
The affected product is CoreBunch Instatic. All releases through 0.0.14 are vulnerable. Users running these versions are at risk, while versions following the remediation patch address the issue. The vulnerability applies to the server island feature that exposes the /_instatic/hole/<nodeId> endpoint.
Risk and Exploitability
The CVSS score of 6.1 classifies the flaw as medium severity, and the EPSS score is not available. The vulnerability is exploitable by any remote user without authentication via a standard HTTP request. No exploit has been reported in CISA KEV. The lack of an EPSS value means the probability of exploitation is unknown, but the remote nature and lack of authentication increase the attack surface. Organizations should treat it as a moderate risk until a patch is applied.
OpenCVE Enrichment