Hugo · Hugo · CVE-2026-100693
**Name of the Vulnerable Software and Affected Versions**
Hugo versions 0.162.0 through 0.165.0
**Description**
A case-sensitive validation flaw exists in the `security.http.urls` IP-literal deny rule. This allows attackers to bypass restrictions by using mixed-case URL schemes in `resources.GetRemote()` calls to fetch data from restricted IP addresses, such as localhost.
**Recommendations**
Update Hugo to version 0.166.0 or later.