PT-2026-99364 · Hugo · Hugo

·

CVE-2026-100693

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hugo versions 0.162.0 through 0.165.0
Description A case-sensitive validation flaw exists in the security.http.urls IP-literal deny rule. This allows attackers to bypass restrictions by using mixed-case URL schemes in resources.GetRemote() calls to fetch data from restricted IP addresses, such as localhost.
Recommendations Update Hugo to version 0.166.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100693
GHSA-PMRV-X7GP-2RJW

Affected Products

Hugo