Vulnerability Description
Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL it is called with, but it did not re-validate intermediate URLs on HTTP 3xx redirects. An allowed server (or an attacker controlling its DNS or response) could therefore redirect the request to a host that the policy was meant to forbid and Hugo would fetch from the redirected target. The same bypass also lifted any host-shape restriction the operator had put in place. This vulnerability is fixed in 0.162.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gohugo | Hugo | >= 0.91.0, < 0.162.0 |
Related Weaknesses (CWE)
References
- https://github.com/gohugoio/hugo/commit/86fbb0f7a8bbb93e2e916390de9e5a4f24bf9f50Patch
- https://github.com/gohugoio/hugo/releases/tag/v0.162.0Release Notes
- https://github.com/gohugoio/hugo/security/advisories/GHSA-vxgm-5rmg-5w8gVendor Advisory
FAQ
What is CVE-2026-50134?
CVE-2026-50134 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL it is called with, but it did not re-validate intermediate URLs on HTTP 3xx redir...
How severe is CVE-2026-50134?
CVE-2026-50134 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-50134?
Check the references section above for vendor advisories and patch information. Affected products include: Gohugo Hugo.