gohugo hugo是gohugo团队开源的一个生成静态网站的框架。 GoHugo Hugo v0.162.0版本至v0.163.0版本存在服务端请求伪造漏洞,该漏洞源于默认的security.http.urls策略对IPv4地址的编码方式检查不完善,导致整数、十六进制或八进制等替代编码方式绕过规则,当模板传递不可信或数据派生的URL给resources.GetRemote且主机平台使用cgo系统解析器时,可对回环地址和内部服务(包括托管或CI构建中的云元数据端点)发起构建时服务端请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58402 | Hugo default code block renderer XSS via unescaped code-fence language | |
| CVE-2026-58403 | Hugo symlink confinement bypass in os.ReadFile | |
| CVE-2026-50134 | Hugo: security.http.urls allow-list bypass via HTTP redirects | |
| CVE-2026-50133 | Hugo: XSS via text/html content files | |
| CVE-2026-50135 | Hugo: Symlink confinement bypass in resources.Get |
No comments yet