Vulnerability DatabaseCVE-2026-100693

CVE-2026-100693: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-100693 is a security feature bypass vulnerability in the Hugo static site generator caused by a case-sensitive validation flaw in the security.http.urls IP-literal deny rule. Affecting Hugo versions v0.162.0 through v0.165.x (before v0.166.0), it allows attackers to bypass outbound fetch restrictions by supplying mixed-case URL schemes (e.g., HTTP://127.0.0.1/) in resources.GetRemote calls, enabling access to restricted IP addresses such as localhost. The vulnerability was published on September 26, 2026, and is classified as High severity with a CVSS v4 base score of 8.6 and a CVSS v3.1 base score of 8.4 (GitHub Advisory, GitHub Advisory DB).

Technical details

The root cause is CWE-178 (Improper Handling of Case Sensitivity): Hugo's default IP-literal deny rule in security.http.urls performed case-sensitive string matching on URL schemes, while all other default security rules were case-insensitive (GitHub Advisory). An attacker who can influence the URL passed to resources.GetRemote — for example, through untrusted template input — can craft a URL with an uppercase or mixed-case scheme (e.g., HTTP://127.0.0.1/, Http://localhost/) that bypasses the deny rule and causes Hugo to fetch content from restricted internal addresses. The attack vector is local (the attacker must be able to supply content to the Hugo build process), requires no privileges, and no user interaction (GitHub Advisory DB).

Impact

Successful exploitation allows an unauthenticated local user to bypass Hugo's outbound HTTP security controls and fetch content from restricted IP addresses such as localhost or other internal network resources during a site build. This can expose sensitive data served on loopback interfaces (e.g., metadata services, internal APIs, or development servers), and may allow unauthorized read access to confidential information, integrity violations through injected content, or disruption of the build process — all rated High impact across confidentiality, integrity, and availability (GitHub Advisory, GitHub Advisory DB).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is 0.0, indicating very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires local access to the Hugo build environment and the ability to influence URLs passed to resources.GetRemote, limiting the practical attack surface to scenarios involving untrusted template content or collaborative/CI build pipelines.

Exploitation steps

  1. Identify target environment: Locate a Hugo build environment running versions v0.162.0–v0.165.x where resources.GetRemote is used and the attacker can influence template content or URL inputs (e.g., a shared CI/CD pipeline or a Hugo site accepting user-contributed content).
  2. Craft a bypass URL: Construct a URL with a mixed-case or uppercase scheme targeting a restricted IP address, such as HTTP://127.0.0.1:8080/sensitive-endpoint or Http://localhost/admin.
  3. Inject the URL into a resources.GetRemote call: Supply the crafted URL as the argument to resources.GetRemote within a Hugo template or content file, bypassing the case-sensitive IP-literal deny rule in security.http.urls.
  4. Trigger the Hugo build: Initiate a Hugo site build (e.g., hugo build) so that the template is processed and the restricted URL is fetched.
  5. Retrieve the response: The fetched content from the restricted internal address is returned to the template and may be rendered into the built site output or accessible to the attacker through build artifacts, exposing sensitive internal data (GitHub Advisory).

Indicators of compromise

  • Logs: Hugo build logs containing resources.GetRemote calls with uppercase or mixed-case URL schemes (e.g., HTTP://, Http://, HTTPS://) targeting loopback or internal IP addresses (127.0.0.1, ::1, 169.254.x.x).
  • Network: Outbound HTTP requests from the Hugo build process to localhost or internal network addresses (127.0.0.1, 0.0.0.0, 169.254.169.254) during build execution.
  • File System: Generated site output files containing unexpected content sourced from internal services or metadata endpoints, indicating successful SSRF-like data exfiltration during the build.

Mitigation and workarounds

Upgrade Hugo to version v0.166.0 or later, which fixes the IP-literal deny rule to perform case-insensitive URL scheme matching (GitHub Advisory). As a workaround for environments that cannot immediately upgrade, avoid passing untrusted or user-controlled URLs to resources.GetRemote, or replace the default deny-based security.http.urls configuration with an explicit allow-list of trusted hosts. Review existing Hugo templates and CI/CD pipelines for any resources.GetRemote calls that accept external input.

Community reactions

The vulnerability was credited to researcher Reload3d, who discovered and reported the flaw to the Hugo project (GitHub Advisory). The Hugo maintainer (bep) published the security advisory and patch promptly. No significant broader media coverage or notable community debate has been observed beyond the standard advisory publication.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

hugo

Fixed

sid

hugo: 0.166.0-1

Fixed

trixie

hugo

Fixed

Ubuntu

Unknown

bionic (esm-apps)

hugo

Unknown

devel

hugo

Unknown

focal (esm-apps)

hugo

Unknown

jammy

hugo

Unknown

jammy (esm-apps)

hugo

Unknown

noble

hugo

Unknown

noble (esm-apps)

hugo

Unknown

resolute

hugo

Unknown

RHEL / CentOS

Affected

RHEL 10

Not Affected

Alpine

Affected

edge

0.164.0-r0

Affected

Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-100692HIGH8.7
  • Grafana logoGrafana
  • grafana.src
NoYesSep 26, 2026
CVE-2026-100690HIGH8.7
  • Grafana logoGrafana
  • hugo
NoYesSep 26, 2026
CVE-2026-100693HIGH8.6
  • NixOS logoNixOS
  • hugo
NoYesSep 26, 2026
CVE-2026-100694MEDIUM5.1
  • Grafana logoGrafana
  • hugo
NoYesSep 26, 2026
CVE-2026-100691MEDIUM5.1
  • Grafana logoGrafana
  • hugo
NoYesSep 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management