CVE-2026-100693 | gohugoio Hugo up to 0.165.x IP-literal deny rule security.http.urls resources.GetRemote input validation
A vulnerability labeled as problematic has been found in gohugoio Hugo up to 0.165.x. Affected is the function resources.GetRemote of the file security.http.urls of the component IP-literal deny rule. Executing a manipulation can lead to improper input validation.
This vulnerability appears as CVE-2026-100693. The attack requires local access. There is no available exploit.
The affected component should be upgraded.VulDB Recent EntriesRead More