Vulnerability Details CVE-2026-100693
Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 2.2%
CVSS Severity
CVSS v3 Score 8.4
Products affected by CVE-2026-100693
-
cpe:2.3:a:gohugo:hugo:0.162.0
-
cpe:2.3:a:gohugo:hugo:0.162.1
-
cpe:2.3:a:gohugo:hugo:0.163.0
-
cpe:2.3:a:gohugo:hugo:0.163.1
-
cpe:2.3:a:gohugo:hugo:0.163.2
-
cpe:2.3:a:gohugo:hugo:0.163.3
-
cpe:2.3:a:gohugo:hugo:0.164.0
-
cpe:2.3:a:gohugo:hugo:0.165.0