{"id":"GHSA-r46f-3rpw-hxrv","summary":"Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)","details":"### Impact\n\n  The default `security.http.urls` policy denies requests to loopback, internal,\n  and cloud-metadata IPv4 literals (e.g. `http://127.0.0.1/`,\n  `http://169.254.169.254/`). The deny rule only matched dotted-decimal notation,\n  so alternate IPv4 encodings of the same addresses — integer, hex, or octal,\n  which contain no dot — passed the policy:\n\n  - `http://2130706433/` → `127.0.0.1`\n  - `http://2852039166/` → `169.254.169.254` (cloud metadata)\n  - `http://0x7f000001/`, `http://017700000001/`, `http://0/`\n\n  When a template passes an untrusted or data-derived URL to\n  `resources.GetRemote` and the host platform uses the\n  cgo system resolver, these encodings resolve to the blocked address — allowing\n  build-time server-side requests to loopback and internal services, including the\n  cloud-metadata endpoint in hosted/CI builds. The same check is reused on\n  redirects, so the gap also applies to each redirect hop.\n\n  This affects sites that rely on `security.http.urls` as a security boundary\n  while fetching attacker-influenced remote URLs; it does not affect sites that\n  fully trust the URLs they fetch.\n\n  ### Patches\n\n  Fixed in **v0.163.1**. Integer/hex/octal IPv4 hosts are now canonicalized to\n  dotted-decimal before the policy is applied, so every encoding of an address is\n  treated alike. No configuration change is required.\n\n  ### Workarounds\n\n  Avoid passing untrusted URLs to `resources.GetRemote`, or\n  tighten `security.http.urls` to an explicit allow-list of trusted hosts.\n\n  ### Affected versions\n\n  v0.162.0 – v0.163.0 (patched in v0.163.1).","aliases":["CVE-2026-58404","GO-2026-5606"],"modified":"2026-07-24T19:26:04.030165670Z","published":"2026-06-19T19:18:14Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-19T19:18:14Z","nvd_published_at":null,"cwe_ids":["CWE-918"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-r46f-3rpw-hxrv"},{"type":"PACKAGE","url":"https://github.com/gohugoio/hugo"}],"affected":[{"package":{"name":"github.com/gohugoio/hugo","ecosystem":"Go","purl":"pkg:golang/github.com/gohugoio/hugo"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.162.0"},{"fixed":"0.163.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-r46f-3rpw-hxrv/GHSA-r46f-3rpw-hxrv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"}]}