Junglewise Threat Intelligence

CVE-2026-10582: Hugo SSRF in resources.GetRemote via security.http.urls allowlist bypass

CVE-2026-10582 · Severity: high · CVSS 7.4 · Published 2026-08-24

Technologies: Hugo. Vendors: Hugo.

Executive brief

Hugo is a static site generator that allows templates and content to fetch remote URLs via the resources.GetRemote function. The security.http.urls allowlist is supposed to restrict which domains can be fetched, but it only inspects the URL text without resolving hostnames or checking the actual IP address being contacted. An attacker who can inject URLs into content fields (such as front-matter or CMS integration) can bypass this control by using a hostname that resolves to internal, private, or cloud metadata addresses, allowing the build process to fetch sensitive internal data that gets embedded in the published site.

Technical details

This is a server-side request forgery (SSRF) vulnerability in Hugo's remote content fetching mechanism. The CheckAllowedHTTPURL function in config/security/securityConfig.go only validates the URL text against a pattern allowlist and canonicalizes IPv4 addresses in text form, but never performs actual hostname resolution or inspects the address to which the HTTP client connects. The HTTP client in resources/resource_factories/create/create.go lacks any dial-time hook to enforce address-level checks. This allows an attacker to provide a URL with a hostname resolving to loopback (127.0.0.1), private (10.0.0.0/8, etc.), or cloud-metadata addresses, bypass the allowlist check, and have the build process fetch and embed the response in the static output artifact. Requires attacker ability to inject URLs through content or front-matter fields accessible during build.

Affected products

  • Hugo Hugo up to v0.165.0 and likely earlier

Timeline

  • 2026-08-24: disclosed: CVE-2026-10582 published
  • 2026-08-24: advisory: NVD advisory published

References

Related threats