Junglewise Threat Intelligence

CVE-2026-16218: hunvreus devpush improper handling of storage reset failure

CVE-2026-16218 · Severity: low · CVSS 2.6 · Published 2026-07-19

Executive brief

hunvreus devpush, an open-source deployment platform, contains a flaw in how it handles storage reset failures. When a user attempts to clear or reset storage and the process fails, the system incorrectly marks the storage as 'active' and healthy instead of reporting a failure. This could lead to data integrity issues where users mistakenly believe old data has been deleted when it actually remains accessible and in use.

Technical details

A vulnerability classified as CWE-703 (Improper Check or Handling of Exceptional Conditions) exists in the reset_storage function within app/workers/tasks/storage.py. When a storage reset operation encounters an exception (such as a volume deletion error), the exception handler records the error message but proceeds to set the storage status to 'active'. An attacker with team administrator privileges could potentially exploit this to maintain the presence of data that was intended to be wiped. The attack requires adjacent network access and has high complexity due to the need to trigger specific underlying system failures during the reset task. As of the advisory date, no official patch has been released by the vendor.

Affected products

  • hunvreus devpush up to 0.4.6

Timeline

  • 2026-06-13: disclosed: Issue reported via GitHub issue #69
  • 2026-07-19: advisory: CVE published by VulDB/NVD

References