
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-100693 is a security feature bypass vulnerability in the Hugo static site generator caused by a case-sensitive validation flaw in the security.http.urls IP-literal deny rule. Affecting Hugo versions v0.162.0 through v0.165.x (before v0.166.0), it allows attackers to bypass outbound fetch restrictions by supplying mixed-case URL schemes (e.g., HTTP://127.0.0.1/) in resources.GetRemote calls, enabling access to restricted IP addresses such as localhost. The vulnerability was published on September 26, 2026, and is classified as High severity with a CVSS v4 base score of 8.6 and a CVSS v3.1 base score of 8.4 (GitHub Advisory, GitHub Advisory DB).
The root cause is CWE-178 (Improper Handling of Case Sensitivity): Hugo's default IP-literal deny rule in security.http.urls performed case-sensitive string matching on URL schemes, while all other default security rules were case-insensitive (GitHub Advisory). An attacker who can influence the URL passed to resources.GetRemote — for example, through untrusted template input — can craft a URL with an uppercase or mixed-case scheme (e.g., HTTP://127.0.0.1/, Http://localhost/) that bypasses the deny rule and causes Hugo to fetch content from restricted internal addresses. The attack vector is local (the attacker must be able to supply content to the Hugo build process), requires no privileges, and no user interaction (GitHub Advisory DB).
Successful exploitation allows an unauthenticated local user to bypass Hugo's outbound HTTP security controls and fetch content from restricted IP addresses such as localhost or other internal network resources during a site build. This can expose sensitive data served on loopback interfaces (e.g., metadata services, internal APIs, or development servers), and may allow unauthorized read access to confidential information, integrity violations through injected content, or disruption of the build process — all rated High impact across confidentiality, integrity, and availability (GitHub Advisory, GitHub Advisory DB).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is 0.0, indicating very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires local access to the Hugo build environment and the ability to influence URLs passed to resources.GetRemote, limiting the practical attack surface to scenarios involving untrusted template content or collaborative/CI build pipelines.
resources.GetRemote is used and the attacker can influence template content or URL inputs (e.g., a shared CI/CD pipeline or a Hugo site accepting user-contributed content).HTTP://127.0.0.1:8080/sensitive-endpoint or Http://localhost/admin.resources.GetRemote call: Supply the crafted URL as the argument to resources.GetRemote within a Hugo template or content file, bypassing the case-sensitive IP-literal deny rule in security.http.urls.hugo build) so that the template is processed and the restricted URL is fetched.resources.GetRemote calls with uppercase or mixed-case URL schemes (e.g., HTTP://, Http://, HTTPS://) targeting loopback or internal IP addresses (127.0.0.1, ::1, 169.254.x.x).Upgrade Hugo to version v0.166.0 or later, which fixes the IP-literal deny rule to perform case-insensitive URL scheme matching (GitHub Advisory). As a workaround for environments that cannot immediately upgrade, avoid passing untrusted or user-controlled URLs to resources.GetRemote, or replace the default deny-based security.http.urls configuration with an explicit allow-list of trusted hosts. Review existing Hugo templates and CI/CD pipelines for any resources.GetRemote calls that accept external input.
The vulnerability was credited to researcher Reload3d, who discovered and reported the flaw to the Hugo project (GitHub Advisory). The Hugo maintainer (bep) published the security advisory and patch promptly. No significant broader media coverage or notable community debate has been observed beyond the standard advisory publication.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
hugo
devel
hugo
focal (esm-apps)
hugo
jammy
hugo
jammy (esm-apps)
hugo
noble
hugo
noble (esm-apps)
hugo
resolute
hugo
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."