github.com/gohugoio/hugo vulnerabilities
CVEs whose affected-version data names the github.com/gohugoio/hugo package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
12 CVEsRSS
CVE-2026-58404HighHugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
CVE-2026-58402MediumHugo: XSS via unescaped code-fence language in default code block renderer
Hugo: XSS via unescaped code-fence language in default code block renderer
CVE-2026-58403MediumHugo: Symlink confinement bypass in os.ReadFile
Hugo: Symlink confinement bypass in os.ReadFile
GHSA-q76j-gcg9-vxc6MediumHugo: XSS via unescaped code-fence language in default code block renderer
Hugo: XSS via unescaped code-fence language in default code block renderer
GHSA-c3wq-j5vh-68rcMediumHugo: Symlink confinement bypass in os.ReadFile
Hugo: Symlink confinement bypass in os.ReadFile
GHSA-r46f-3rpw-hxrvHighHugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
CVE-2026-50133MediumHugo: XSS via text/html content files
Hugo: XSS via text/html content files
CVE-2026-50134MediumHugo: security.http.urls allow-list bypass via HTTP redirects
Hugo: security.http.urls allow-list bypass via HTTP redirects
CVE-2026-50135MediumHugo: Symlink confinement bypass in resources.Get
Hugo: Symlink confinement bypass in resources.Get
CVE-2026-44301MediumHugo's Node tool execution allows file system access outside the project directory
Hugo's Node tool execution allows file system access outside the project directory
CVE-2026-35166MediumHugo: Certain markdown links are not properly escaped
Hugo: Certain markdown links are not properly escaped
CVE-2020-26284High· 7.7Hugo can execute a binary from the current directory on Windows
Hugo can execute a binary from the current directory on Windows