OurCVEs
Register
Back to feed
High
DEBIAN-CVE-2026-100693

Published Sep 26, 2026

CVSS

8.4

HIGH

EPSS

Exploit Prediction Scoring System — the modeled probability of in-the-wild exploitation in the next 30 days.
—

Affected packages

0
Summary

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost.

Developer impact

Recommended action

Affected packages
Sources