{"id":"GHSA-vxgm-5rmg-5w8g","summary":"Hugo: security.http.urls allow-list bypass via HTTP redirects","details":"**Commit:** [86fbb0f7a8](https://github.com/gohugoio/hugo/commit/86fbb0f7a8) — _security: Validate redirects against security.http.urls_\n**Affected versions:** v0.91.0 (when `security.http.urls` was introduced) through v0.161.1.\n**Fixed in:** v0.162.0.\n**Severity:** Only relevant for sites that rely on `security.http.urls` as a trust boundary — e.g. CI builds that fetch remote resources but want to constrain which hosts can be reached. Not an issue if you fully trust every URL passed to `resources.GetRemote`.\n\n**Description.** `resources.GetRemote` enforces `security.http.urls` on the URL it is called with, but until v0.162.0 it did not re-validate intermediate URLs on HTTP 3xx redirects. An allowed server (or an attacker controlling its DNS or response) could therefore redirect the request to a host that the policy was meant to forbid — for example, `http://localhost/` or an internal IP — and Hugo would fetch from the redirected target. The same bypass also lifted any host-shape restriction the operator had put in place.\n\n**Mitigation.** v0.162.0 installs a `CheckRedirect` on the HTTP client used by `resources.GetRemote` that re-runs `security.http.urls` on every redirect target and caps the redirect chain at 10 hops. No configuration change is required.","aliases":["CVE-2026-50134","GO-2026-5681"],"modified":"2026-07-07T20:41:31.690643411Z","published":"2026-06-16T19:22:37Z","database_specific":{"cwe_ids":["CWE-918"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-16T19:22:37Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-vxgm-5rmg-5w8g"},{"type":"WEB","url":"https://github.com/gohugoio/hugo/commit/86fbb0f7a8bbb93e2e916390de9e5a4f24bf9f50"},{"type":"PACKAGE","url":"https://github.com/gohugoio/hugo"},{"type":"WEB","url":"https://github.com/gohugoio/hugo/releases/tag/v0.162.0"}],"affected":[{"package":{"name":"github.com/gohugoio/hugo","ecosystem":"Go","purl":"pkg:golang/github.com/gohugoio/hugo"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.91.0"},{"fixed":"0.162.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-vxgm-5rmg-5w8g/GHSA-vxgm-5rmg-5w8g.json"}}],"schema_version":"1.9.0"}