CVE-2026-10582 | gohugoio Hugo up to 0.165.0 security.http.urls allowlist securityConfig.go resources.GetRemote infinite loop
A vulnerability described as problematic has been identified in gohugoio Hugo up to 0.165.0. This affects the function resources.GetRemote of the file config/security/securityConfig.go of the component security.http.urls allowlist. Such manipulation leads to infinite loop.
This vulnerability is documented as CVE-2026-10582. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More