HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-100693 — Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation ...

·Source: NIST NVD

Updated:

Executive Summary

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost.

Analysis

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost. CVSS Score: 8.4. Published: 2026-09-26T14:16:54.007.

Indicators of Compromise (1)

CVE (1)
CVE-2026-100693
Source Attribution

Originally published by NIST NVD on Sep 26, 2026. Verified by: NIST.

Related Threats