Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-178"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100693.json"
}