Junglewise Threat Intelligence

CVE-2026-35166: GO-2026-5504 - Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo

CVE-2026-35166 · Severity: medium · CVSS 4 · Published 2026-07-07

Technologies: github.com/gohugoio/hugo (Go). Vendors: Go.

Executive brief

Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo

Affected products

  • Go github.com/gohugoio/hugo

Related threats