Known Vulnerabilities for products from Gohugo
Listed below are 16 of the newest known vulnerabilities associated with the vendor "Gohugo".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100694 json | Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type a... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-100693 json | Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal den... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-100692 json | Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at... | Not Provided | 2026-09-26 | 2026-09-29 |
| CVE-2026-100691 json | Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not esc... | Not Provided | 2026-09-26 | 2026-09-29 |
| CVE-2026-100690 json | Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js per... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-75926 json | Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel,... | Not Provided | 2026-08-18 | 2026-09-29 |
| CVE-2026-58404 json | Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loo... | Not Provided | 2026-07-06 | 2026-07-08 |
| CVE-2026-58403 json | Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files under a ... | Not Provided | 2026-07-06 | 2026-07-08 |
| CVE-2026-58402 json | Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence ... | Not Provided | 2026-07-06 | 2026-07-08 |
| CVE-2026-50135 json | Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows ... | Not Provided | 2026-07-06 | 2026-07-08 |
| CVE-2026-50134 json | Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL it is ... | Not Provided | 2026-07-06 | 2026-07-08 |
| CVE-2026-50133 json | Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the ... | Not Provided | 2026-07-06 | 2026-07-08 |
| CVE-2026-44301 json | Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipelines ... | Not Provided | 2026-05-12 | 2026-05-21 |
| CVE-2026-35166 json | Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML rendere... | Not Provided | 2026-04-06 | 2026-04-20 |
| CVE-2026-10618 json | Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTM... | Not Provided | 2026-08-24 | 2026-09-29 |
| CVE-2020-26284 json | Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's `os/exec` for certain features, e.g. for ... | 8.5 - HIGH | 2020-12-21 | 2020-12-23 |
Known software with vulnerabilities from Gohugo
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Gohugo | Hugo | - |