CVE-2026-100693 | gohugoio Hugo up to 0.165.x IP-literal deny rule security.http.urls resources.GetRemote input validation

SecurityVulns

A vulnerability labeled as problematic has been found in gohugoio Hugo up to 0.165.x. Affected is the function resources.GetRemote of the file security.http.urls of the component IP-literal deny rule. Executing a manipulation can lead to improper input validation.

This vulnerability appears as CVE-2026-100693. The attack requires local access. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More