#1146720 hugo: CVE-2026-10582 CVE-2026-10618

Package:
src:hugo
Source:
src:hugo
Submitter:
Salvatore Bonaccorso
Date:
2026-09-19 20:39:02 UTC
Severity:
normal
Tags:
#1146720#5
Date:
2026-09-04 18:57:30 UTC
From:
To:
Hi,

The following vulnerabilities were published for hugo.

CVE-2026-10582[0]:
| Hugo's security.http.urls allowlist is the only control on outbound
| fetches made by resources.GetRemote, and it inspects the URL text
| alone. CheckAllowedHTTPURL in config/security/securityConfig.go
| applies the configured pattern list and then re-checks a
| canonicalised form of an integer, hex or octal IPv4 host, but it
| never resolves the hostname and never inspects the address the HTTP
| client actually connects to. The client constructed in
| resources/resource_factories/create/create.go installs no dial-time
| hook, so no check occurs at connection time either. A hostname that
| resolves to a loopback, private or cloud-metadata address therefore
| satisfies the policy, and the response body is embedded in the
| generated site. An attacker who can supply a URL through content,
| for example a front-matter field or a CMS field, can make the build
| fetch an internal endpoint and publish the response in the static
| output, so the build artifact itself carries the data out.


CVE-2026-10618[1]:
| Hugo's default fenced-code-block renderer writes attribute values
| taken from the code-fence info string into the rendered HTML without
| escaping them. New in markup/internal/attributes/attributes.go
| converts every attribute value from a byte slice to a string as it
| is stored, deliberately dropping the escaping that used to happen
| there, and RenderAttributes in the same file escapes only values
| that are still byte slices, so its escaping branch is never reached
| and every value is written verbatim. The function's documentation
| states that it performs HTML escaping of string attributes, which it
| does not. A quote inside an attribute value in the info string
| therefore terminates the attribute and allows a further attribute,
| including an event handler, to be placed on the wrapper element, and
| the script runs for every visitor who loads the page. This path is
| reached under the default configuration, with code fences enabled
| and without goldmark's unsafe setting or any custom render hook.
| Attribute names beginning with on are filtered when the attributes
| are parsed, so injection is achieved through the value rather than
| the name.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-10582
https://www.cve.org/CVERecord?id=CVE-2026-10582
[1] https://security-tracker.debian.org/tracker/CVE-2026-10618
https://www.cve.org/CVERecord?id=CVE-2026-10618
[2] https://github.com/gohugoio/hugo/issues/15247

Regards,
Salvatore

#1146720#12
Date:
2026-09-19 20:37:16 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
hugo, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1146720@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Dr. Tobias Quathamer <toddy@debian.org> (supplier of updated hugo package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 19 Sep 2026 22:05:30 +0200
Source: hugo
Architecture: source
Version: 0.166.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
Changed-By: Dr. Tobias Quathamer <toddy@debian.org>
Closes: 1146720
Changes:
 hugo (0.166.0-1) unstable; urgency=medium
 .
   * New upstream version 0.166.0 (Closes: #1146720)
     - Refresh patches
     - Ignore two tests due to internet connection
     - Build-Depend on golang-github-gobwas-glob-dev (>= 1.0.0)
 .
     - CVE-2026-10582
       Hugo's security.http.urls allowlist is the only control on outbound
       fetches made by resources.GetRemote, and it inspects the URL text alone.
       CheckAllowedHTTPURL in config/security/securityConfig.go applies the
       configured pattern list and then re-checks a canonicalised form of an
       integer, hex or octal IPv4 host, but it never resolves the hostname and
       never inspects the address the HTTP client actually connects to. The
       client constructed in resources/resource_factories/create/create.go
       installs no dial-time hook, so no check occurs at connection time
       either. A hostname that resolves to a loopback, private or
       cloud-metadata address therefore satisfies the policy, and the response
       body is embedded in the generated site. An attacker who can supply a URL
       through content, for example a front-matter field or a CMS field, can
       make the build fetch an internal endpoint and publish the response in
       the static output, so the build artifact itself carries the data out.
 .
     - CVE-2026-10618
       Hugo's default fenced-code-block renderer writes attribute values taken
       from the code-fence info string into the rendered HTML without escaping
       them. New in markup/internal/attributes/attributes.go converts every
       attribute value from a byte slice to a string as it is stored,
       deliberately dropping the escaping that used to happen there, and
       RenderAttributes in the same file escapes only values that are still
       byte slices, so its escaping branch is never reached and every value is
       written verbatim. The function's documentation states that it performs
       HTML escaping of string attributes, which it does not. A quote inside an
       attribute value in the info string therefore terminates the attribute
       and allows a further attribute, including an event handler, to be placed
       on the wrapper element, and the script runs for every visitor who loads
       the page. This path is reached under the default configuration, with
       code fences enabled and without goldmark's unsafe setting or any custom
       render hook. Attribute names beginning with on are filtered when the
       attributes are parsed, so injection is achieved through the value rather
       than the name.
Checksums-Sha1:
 3d5d9d32c9b13a56834cc9a7d82723b6e9842573 6569 hugo_0.166.0-1.dsc
 ce81c4813d2bb978a28f5666dd0407db220af9ba 9885828 hugo_0.166.0.orig.tar.xz
 ccc8606166f92e22d1ac66205176fd511a714887 609912 hugo_0.166.0-1.debian.tar.xz
 5df0a141fea32e994646ba5bcd04f9cfba4018ef 15992240 hugo_0.166.0-1.git.tar.xz
 de03ac68ce721e741af14ef5a4d6349d74650e88 17718 hugo_0.166.0-1_source.buildinfo
Checksums-Sha256:
 158b526d6ea5a9ae8b7a8503610892440c7157b40d2755d8d8385736866f5a4f 6569 hugo_0.166.0-1.dsc
 903d048049a55d7ebdee6ce2378c4a5322d51c5e72a213d83047485eab8a6e83 9885828 hugo_0.166.0.orig.tar.xz
 c96e4e9b501d81123b051deebc8afdb923dd2c69b6eef4e563176be7e493033c 609912 hugo_0.166.0-1.debian.tar.xz
 6ac7cd0c30d4c61529417da7cfda43af2c10c74daecf49d7f1b2d0f528c1d711 15992240 hugo_0.166.0-1.git.tar.xz
 90e79c9ca7656ef20cd904359096434100398e45ee81cb1790f95a27f1db92e2 17718 hugo_0.166.0-1_source.buildinfo
Files:
 482f730014c3e1aeb09e534d18c67a7f 6569 web optional hugo_0.166.0-1.dsc
 b36d6cc285144aa3a601c3be90617556 9885828 web optional hugo_0.166.0.orig.tar.xz
 7f8fdcc60a08f4003b8eb31533a39815 609912 web optional hugo_0.166.0-1.debian.tar.xz
 a2b80bb98e1a2b5d59940d50fc009e8b 15992240 web None hugo_0.166.0-1.git.tar.xz
 31e558c04b915d3a1949dfecd95735ed 17718 web optional hugo_0.166.0-1_source.buildinfo
Git-Tag-Info: tag=6f86d39bb1289717eea8ef21f3f668db087ea599 fp=d1cb8f39bc5ded24c5d2c78c1302f1f036ebeb19
Git-Tag-Tagger: Dr. Tobias Quathamer <toddy@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqu7XYACgkQYG0ITkaD
wHlAnxAAnqBD8D3MBP2OtdkH5CawmN9BaFIY4ymnbi9KMXtsFmUMIUo9AMCqqWdH
dxpEER0HPMdHhjhQrJ7zvoThLGxUwW1eJqMiC4aywxXMn3BYS0W4X25xc6N1+EnD
NhCFxKfKCTMszskWhrYtayR8JnCsHoQLaoZWlIeXuZpy/ccOYeB+dck1xC+z4CZL
NOoSJ+OUVD7CkEU/Az9gEEiHp0tHiWteHWQvYp0h3eD5cbMrDXy1Ihvn71tUxZGF
cYmLvVkG3QrVnxg9kE7ERAAYDlBVGAzWxVxaXbb+NXgIUCCcyNbo5gEAIKLWvvZP
lRXrZDj1BlVbhjX81qYiI3J4sgNF3XNHGHvKSi6f2nELDubkGs7ZyqBAjhgu9d+6
VbVSTWPMmOd1p3BFW8g0Hy7wAXTKdKQ+8xGNr31HLO7ghkIZUZk8JC9HpnkFCNcr
TY4gM8CH2292H/oP5nDXdkKxxsNla1q46CAA8Fh8Gyht9i06UehqMNUH+oa1/1o1
Exu+BVpKF2anDw84E/v/RXtNIYZGpwwFV3nvIqADHfm+wnftoC15eU7xsm+Lc95h
Ocj8BJsoelYtdQGO9dvEWlCl1ojMuXSg6hNg1KzwY1AOpWh47msJhVShnjgB1W5v
adZwYYghz6/FmTYLeWS1Q0hwF4ZXswcHK/MgQvXz+JmXAPyQ2XI=
=KkPs
-----END PGP SIGNATURE-----