We believe that the bug you reported is fixed in the latest version of
hugo, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1146720@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Dr. Tobias Quathamer <toddy@debian.org> (supplier of updated hugo package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 19 Sep 2026 22:05:30 +0200
Source: hugo
Architecture: source
Version: 0.166.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
Changed-By: Dr. Tobias Quathamer <toddy@debian.org>
Closes: 1146720
Changes:
hugo (0.166.0-1) unstable; urgency=medium
.
* New upstream version 0.166.0 (Closes: #1146720)
- Refresh patches
- Ignore two tests due to internet connection
- Build-Depend on golang-github-gobwas-glob-dev (>= 1.0.0)
.
- CVE-2026-10582
Hugo's security.http.urls allowlist is the only control on outbound
fetches made by resources.GetRemote, and it inspects the URL text alone.
CheckAllowedHTTPURL in config/security/securityConfig.go applies the
configured pattern list and then re-checks a canonicalised form of an
integer, hex or octal IPv4 host, but it never resolves the hostname and
never inspects the address the HTTP client actually connects to. The
client constructed in resources/resource_factories/create/create.go
installs no dial-time hook, so no check occurs at connection time
either. A hostname that resolves to a loopback, private or
cloud-metadata address therefore satisfies the policy, and the response
body is embedded in the generated site. An attacker who can supply a URL
through content, for example a front-matter field or a CMS field, can
make the build fetch an internal endpoint and publish the response in
the static output, so the build artifact itself carries the data out.
.
- CVE-2026-10618
Hugo's default fenced-code-block renderer writes attribute values taken
from the code-fence info string into the rendered HTML without escaping
them. New in markup/internal/attributes/attributes.go converts every
attribute value from a byte slice to a string as it is stored,
deliberately dropping the escaping that used to happen there, and
RenderAttributes in the same file escapes only values that are still
byte slices, so its escaping branch is never reached and every value is
written verbatim. The function's documentation states that it performs
HTML escaping of string attributes, which it does not. A quote inside an
attribute value in the info string therefore terminates the attribute
and allows a further attribute, including an event handler, to be placed
on the wrapper element, and the script runs for every visitor who loads
the page. This path is reached under the default configuration, with
code fences enabled and without goldmark's unsafe setting or any custom
render hook. Attribute names beginning with on are filtered when the
attributes are parsed, so injection is achieved through the value rather
than the name.
Checksums-Sha1:
3d5d9d32c9b13a56834cc9a7d82723b6e9842573 6569 hugo_0.166.0-1.dsc
ce81c4813d2bb978a28f5666dd0407db220af9ba 9885828 hugo_0.166.0.orig.tar.xz
ccc8606166f92e22d1ac66205176fd511a714887 609912 hugo_0.166.0-1.debian.tar.xz
5df0a141fea32e994646ba5bcd04f9cfba4018ef 15992240 hugo_0.166.0-1.git.tar.xz
de03ac68ce721e741af14ef5a4d6349d74650e88 17718 hugo_0.166.0-1_source.buildinfo
Checksums-Sha256:
158b526d6ea5a9ae8b7a8503610892440c7157b40d2755d8d8385736866f5a4f 6569 hugo_0.166.0-1.dsc
903d048049a55d7ebdee6ce2378c4a5322d51c5e72a213d83047485eab8a6e83 9885828 hugo_0.166.0.orig.tar.xz
c96e4e9b501d81123b051deebc8afdb923dd2c69b6eef4e563176be7e493033c 609912 hugo_0.166.0-1.debian.tar.xz
6ac7cd0c30d4c61529417da7cfda43af2c10c74daecf49d7f1b2d0f528c1d711 15992240 hugo_0.166.0-1.git.tar.xz
90e79c9ca7656ef20cd904359096434100398e45ee81cb1790f95a27f1db92e2 17718 hugo_0.166.0-1_source.buildinfo
Files:
482f730014c3e1aeb09e534d18c67a7f 6569 web optional hugo_0.166.0-1.dsc
b36d6cc285144aa3a601c3be90617556 9885828 web optional hugo_0.166.0.orig.tar.xz
7f8fdcc60a08f4003b8eb31533a39815 609912 web optional hugo_0.166.0-1.debian.tar.xz
a2b80bb98e1a2b5d59940d50fc009e8b 15992240 web None hugo_0.166.0-1.git.tar.xz
31e558c04b915d3a1949dfecd95735ed 17718 web optional hugo_0.166.0-1_source.buildinfo
Git-Tag-Info: tag=6f86d39bb1289717eea8ef21f3f668db087ea599 fp=d1cb8f39bc5ded24c5d2c78c1302f1f036ebeb19
Git-Tag-Tagger: Dr. Tobias Quathamer <toddy@debian.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqu7XYACgkQYG0ITkaD
wHlAnxAAnqBD8D3MBP2OtdkH5CawmN9BaFIY4ymnbi9KMXtsFmUMIUo9AMCqqWdH
dxpEER0HPMdHhjhQrJ7zvoThLGxUwW1eJqMiC4aywxXMn3BYS0W4X25xc6N1+EnD
NhCFxKfKCTMszskWhrYtayR8JnCsHoQLaoZWlIeXuZpy/ccOYeB+dck1xC+z4CZL
NOoSJ+OUVD7CkEU/Az9gEEiHp0tHiWteHWQvYp0h3eD5cbMrDXy1Ihvn71tUxZGF
cYmLvVkG3QrVnxg9kE7ERAAYDlBVGAzWxVxaXbb+NXgIUCCcyNbo5gEAIKLWvvZP
lRXrZDj1BlVbhjX81qYiI3J4sgNF3XNHGHvKSi6f2nELDubkGs7ZyqBAjhgu9d+6
VbVSTWPMmOd1p3BFW8g0Hy7wAXTKdKQ+8xGNr31HLO7ghkIZUZk8JC9HpnkFCNcr
TY4gM8CH2292H/oP5nDXdkKxxsNla1q46CAA8Fh8Gyht9i06UehqMNUH+oa1/1o1
Exu+BVpKF2anDw84E/v/RXtNIYZGpwwFV3nvIqADHfm+wnftoC15eU7xsm+Lc95h
Ocj8BJsoelYtdQGO9dvEWlCl1ojMuXSg6hNg1KzwY1AOpWh47msJhVShnjgB1W5v
adZwYYghz6/FmTYLeWS1Q0hwF4ZXswcHK/MgQvXz+JmXAPyQ2XI=
=KkPs
-----END PGP SIGNATURE-----