Loading market data...
← Back to CVE feed

CVE-2026-100693

HIGH CVSS 8.4 View on NVD ↗

Description

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: Sep 26, 2026 14:16 UTC Modified: Sep 26, 2026 14:16 UTC