VulnSea

github.com/gohugoio/hugo vulnerabilities

CVEs whose affected-version data names the github.com/gohugoio/hugo package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

12 CVEsRSS

CVE-2026-58404High
3mo ago

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

Twilightgohugoio · github.com/gohugoio/hugoEPSS 0.37%via OSV
CVE-2026-58402Medium
3mo ago

Hugo: XSS via unescaped code-fence language in default code block renderer

Hugo: XSS via unescaped code-fence language in default code block renderer

Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.30%via OSV
CVE-2026-58403Medium
3mo ago

Hugo: Symlink confinement bypass in os.ReadFile

Hugo: Symlink confinement bypass in os.ReadFile

Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.47%via OSV
GHSA-q76j-gcg9-vxc6Medium
3mo ago

Hugo: XSS via unescaped code-fence language in default code block renderer

Hugo: XSS via unescaped code-fence language in default code block renderer

Sunlitgohugoio · github.com/gohugoio/hugovia GHSA
GHSA-c3wq-j5vh-68rcMedium
3mo ago

Hugo: Symlink confinement bypass in os.ReadFile

Hugo: Symlink confinement bypass in os.ReadFile

Sunlitgohugoio · github.com/gohugoio/hugovia GHSA
GHSA-r46f-3rpw-hxrvHigh
3mo ago

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

Twilightgohugoio · github.com/gohugoio/hugovia GHSA
CVE-2026-50133Medium
3mo ago

Hugo: XSS via text/html content files

Hugo: XSS via text/html content files

Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.33%via GHSA
CVE-2026-50134Medium
3mo ago

Hugo: security.http.urls allow-list bypass via HTTP redirects

Hugo: security.http.urls allow-list bypass via HTTP redirects

Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.40%via GHSA
CVE-2026-50135Medium
3mo ago

Hugo: Symlink confinement bypass in resources.Get

Hugo: Symlink confinement bypass in resources.Get

Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.41%via GHSA
CVE-2026-44301Medium
4mo ago

Hugo's Node tool execution allows file system access outside the project directory

Hugo's Node tool execution allows file system access outside the project directory

Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.27%via OSV
CVE-2026-35166Medium
5mo ago

Hugo: Certain markdown links are not properly escaped

Hugo: Certain markdown links are not properly escaped

Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.18%via OSV
CVE-2020-26284High· 7.7
5y ago

Hugo can execute a binary from the current directory on Windows

Hugo can execute a binary from the current directory on Windows

Twilightgohugoio · github.com/gohugoio/hugoEPSS 1.5%via OSV
github.com/gohugoio/hugo vulnerabilities (CVEs) · VulnSea