PT-2026-99364 · Hugo · Hugo
CVSS v4.0
8.6
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hugo versions 0.162.0 through 0.165.0
Description
A case-sensitive validation flaw exists in the
security.http.urls IP-literal deny rule. This allows attackers to bypass restrictions by using mixed-case URL schemes in resources.GetRemote() calls to fetch data from restricted IP addresses, such as localhost.Recommendations
Update Hugo to version 0.166.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hugo