CVE-2026-100693: Hugo v0.162.0 before v0.166.0 IP-literal Deny Rule Bypass

Published Sep 26, 2026
·
Updated

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost.

Affected Software

1 affected component
Hugo Hugo>=0.162.0<0.166.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade gohugoio/hugo to a version that resolves this vulnerability.

    Fixed in 0.166.0

Event History

Sep 26, 2026
CVE Published
via MITRE·01:23 PM
Data Sourced
via MITRE·01:23 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Hugo installations running versions from v0.162.0 up to, but not including, v0.166.0 are affected when they use resources.GetRemote and rely on the security.http.urls IP-literal deny rule to prevent access to restricted addresses.

2

What does an attacker need to exploit the bypass?

An attacker needs a way to cause a resources.GetRemote call to use a mixed-case URL scheme. The mixed-case scheme can bypass the case-sensitive IP-literal validation and allow fetching from restricted IP addresses such as localhost.

3

Does this affect Hugo's default configuration?

The available information identifies exposure specifically where the security.http.urls IP-literal deny rule is relied upon. It does not state whether that rule is enabled or effective in Hugo's default configuration.

4

How can I determine whether an installation is affected?

Check whether the Hugo version is v0.162.0 or later but earlier than v0.166.0, and review templates or other content paths for resources.GetRemote usage. Prioritize cases where remote URLs may be influenced by untrusted input and IP-literal deny rules are used to restrict localhost or other internal addresses.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203