PT-2026-50157 · Hugo · Hugo

CVE-2026-50134

·

Published

2026-06-16

·

Updated

2026-07-30

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hugo versions 0.91.0 through 0.161.1
Description The resources.GetRemote function enforces the security.http.urls policy on the initial URL provided, but it fails to re-validate intermediate URLs during HTTP 3xx redirects. This allows a trusted server, or an attacker controlling its DNS or response, to redirect the request to a forbidden host, such as http://localhost/ or an internal IP address. This bypass also nullifies any host-shape restrictions implemented by the operator.
Recommendations Update to version 0.162.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50134
GHSA-VXGM-5RMG-5W8G
GO-2026-5681
OPENSUSE-SU-2026:21483-1
RHSA-2026:24577

Affected Products

Hugo