Known Vulnerabilities for Hugo by Gohugo
Listed below are 10 of the newest known vulnerabilities associated with "Hugo" by "Gohugo".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100694 json | Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type a... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-100693 json | Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal den... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-100692 json | Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at... | Not Provided | 2026-09-26 | 2026-09-28 |
| CVE-2026-100691 json | Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not esc... | Not Provided | 2026-09-26 | 2026-09-28 |
| CVE-2026-100690 json | Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js per... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-89259 json | Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — i... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89258 json | Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not drop... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-75926 json | Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel,... | Not Provided | 2026-08-18 | 2026-09-24 |
| CVE-2026-58404 json | Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loo... | Not Provided | 2026-07-06 | 2026-07-07 |
| CVE-2026-58403 json | Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files under a ... | Not Provided | 2026-07-06 | 2026-07-06 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gohugo | Hugo | 0.9 | |||
| Application | Gohugo | Hugo | 0.9 | |||
| Application | Gohugo | Hugo | 0.9 | |||
| Application | Gohugo | Hugo | 0.9 | |||
| Application | Gohugo | Hugo | 0.8 | |||
| Application | Gohugo | Hugo | 0.8 | |||
| Application | Gohugo | Hugo | 0.8 | |||
| Application | Gohugo | Hugo | 0.8 | |||
| Application | Gohugo | Hugo | 0.79.1 | |||
| Application | Gohugo | Hugo | 0.79.1 | |||
| Application | Gohugo | Hugo | 0.79.1 | |||
| Application | Gohugo | Hugo | 0.79.0 | |||
| Application | Gohugo | Hugo | 0.79.0 | |||
| Application | Gohugo | Hugo | 0.79.0 | |||
| Application | Gohugo | Hugo | 0.78.2 | |||
| Application | Gohugo | Hugo | 0.78.2 | |||
| Application | Gohugo | Hugo | 0.78.2 | |||
| Application | Gohugo | Hugo | 0.78.1 | |||
| Application | Gohugo | Hugo | 0.78.1 | |||
| Application | Gohugo | Hugo | 0.78.1 |