{"id":"CVE-2026-50134","aliases":["GHSA-vxgm-5rmg-5w8g","GO-2026-5681"],"url":"https://o3.security/vulnerability/CVE-2026-50134","summary":"Hugo: security.http.urls allow-list bypass via HTTP redirects","details":"Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL it is called with, but it did not re-validate intermediate URLs on HTTP 3xx redirects. An allowed server (or an attacker controlling its DNS or response) could therefore redirect the request to a host that the policy was meant to forbid and Hugo would fetch from the redirected target. The same bypass also lifted any host-shape restriction the operator had put in place. This vulnerability is fixed in 0.162.0.","published":"2026-07-06T19:42:49.280Z","modified":"2026-08-12T03:51:46.214571502Z","cvss":null,"epss":{"score":0.00249,"percentile":0.1663,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/gohugoio/hugo","fixedVersion":"0.162.0"}],"fix":{"url":"https://github.com/gohugoio/hugo/commit/86fbb0f7a8bbb93e2e916390de9e5a4f24bf9f50","label":"gohugoio/hugo@86fbb0f"},"references":[{"type":"WEB","url":"https://github.com/gohugoio/hugo/releases/tag/v0.162.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50134.json"},{"type":"ADVISORY","url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-vxgm-5rmg-5w8g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50134"},{"type":"FIX","url":"https://github.com/gohugoio/hugo/commit/86fbb0f7a8bbb93e2e916390de9e5a4f24bf9f50"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:46.214571502Z"}}