CVE-2026-58404High▾ TwilightHugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.4%
The default security.http.urls policy denies requests to loopback, internal,
and cloud-metadata IPv4 literals (e.g. http://127.0.0.1/,
http://169.254.169.254/). The deny rule only matched dotted-decimal notation,
so alternate IPv4 encodings of the same addresses — integer, hex, or octal,
which contain no dot — passed the policy:
http://2130706433/ → 127.0.0.1http://2852039166/ → 169.254.169.254 (cloud metadata)http://0x7f000001/, http://017700000001/, http://0/When a template passes an untrusted or data-derived URL to
resources.GetRemote and the host platform uses the
cgo system resolver, these encodings resolve to the blocked address — allowing
build-time server-side requests to loopback and internal services, including the
cloud-metadata endpoint in hosted/CI builds. The same check is reused on
redirects, so the gap also applies to each redirect hop.
This affects sites that rely on security.http.urls as a security boundary
while fetching attacker-influenced remote URLs; it does not affect sites that
fully trust the URLs they fetch.
Fixed in v0.163.1. Integer/hex/octal IPv4 hosts are now canonicalized to dotted-decimal before the policy is applied, so every encoding of an address is treated alike. No configuration change is required.
Avoid passing untrusted URLs to resources.GetRemote, or
tighten security.http.urls to an explicit allow-list of trusted hosts.
v0.162.0 – v0.163.0 (patched in v0.163.1).
github.com/gohugoio/hugo >= 0.162.0, < 0.163.1Upgrade to a patched release:
github.com/gohugoio/hugo 0.163.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44301MediumHugo's Node tool execution allows file system access outside the project directory
CVE-2026-58402MediumHugo: XSS via unescaped code-fence language in default code block renderer
CVE-2026-35166MediumHugo: Certain markdown links are not properly escaped
CVE-2026-58403MediumHugo: Symlink confinement bypass in os.ReadFile
GHSA-r46f-3rpw-hxrvHighHugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
CVE-2020-26284High· 7.7Hugo can execute a binary from the current directory on Windows