CVE-2026-50134: CWE-918: Server-Side Request Forgery (SSRF) in gohugoio hugo
Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL it is called with, but it did not re-validate intermediate URLs on HTTP 3xx redirects. An allowed server (or an attacker controlling its DNS or response) could therefore redirect the request to a host that the policy was meant to forbid and Hugo would fetch from the redirected target. The same bypass also lifted any host-shape restriction the operator had put in place. This vulnerability is fixed in 0.162.0.
AI Analysis
Technical Summary
Hugo versions >=0.91.0 and <0.162.0 contain an SSRF vulnerability (CWE-918) in the resources.GetRemote function. While the function enforces security.http.urls on the initial URL, it fails to re-validate intermediate URLs during HTTP 3xx redirects. This flaw allows an attacker controlling an allowed server or its DNS/response to redirect requests to hosts that should be forbidden by policy, effectively bypassing host restrictions. The vulnerability is addressed in version 0.162.0.
Potential Impact
An attacker able to control a server or its DNS responses that Hugo fetches from can redirect requests to arbitrary hosts that are otherwise blocked by the configured URL allowlist. This bypass can lead to unauthorized internal or external resource access via SSRF, potentially exposing sensitive information or enabling further attacks. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade Hugo to version 0.162.0 or later, where this SSRF vulnerability is fixed by proper re-validation of URLs on HTTP redirects. No other mitigation is documented or recommended. Patch status is confirmed fixed in 0.162.0.
CVE-2026-50134: CWE-918: Server-Side Request Forgery (SSRF) in gohugoio hugo
Description
Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL it is called with, but it did not re-validate intermediate URLs on HTTP 3xx redirects. An allowed server (or an attacker controlling its DNS or response) could therefore redirect the request to a host that the policy was meant to forbid and Hugo would fetch from the redirected target. The same bypass also lifted any host-shape restriction the operator had put in place. This vulnerability is fixed in 0.162.0.
CVSS v4.0
Score 6.3medium
Affected software
pkg:golang/github.com/gohugoio/hugoRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Hugo versions >=0.91.0 and <0.162.0 contain an SSRF vulnerability (CWE-918) in the resources.GetRemote function. While the function enforces security.http.urls on the initial URL, it fails to re-validate intermediate URLs during HTTP 3xx redirects. This flaw allows an attacker controlling an allowed server or its DNS/response to redirect requests to hosts that should be forbidden by policy, effectively bypassing host restrictions. The vulnerability is addressed in version 0.162.0.
Potential Impact
An attacker able to control a server or its DNS responses that Hugo fetches from can redirect requests to arbitrary hosts that are otherwise blocked by the configured URL allowlist. This bypass can lead to unauthorized internal or external resource access via SSRF, potentially exposing sensitive information or enabling further attacks. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade Hugo to version 0.162.0 or later, where this SSRF vulnerability is fixed by proper re-validation of URLs on HTTP redirects. No other mitigation is documented or recommended. Patch status is confirmed fixed in 0.162.0.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-03T18:49:32.275Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4c076827e9c7971920cbad
Added to database: 07/06/2026, 19:52:08 UTC
Last enriched: 07/14/2026, 08:54:00 UTC
Last updated: 08/20/2026, 22:52:13 UTC
Views: 95
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.