Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/gohugoio/hugo
  4. ›
  5. GHSA-r46f-3rpw-hxrv

GHSA-r46f-3rpw-hxrv: Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

June 19, 2026

The default security.http.urls policy denies requests to loopback, internal, and cloud-metadata IPv4 literals (e.g. http://127.0.0.1/, http://169.254.169.254/). The deny rule only matched dotted-decimal notation, so alternate IPv4 encodings of the same addresses — integer, hex, or octal, which contain no dot — passed the policy:

  • http://2130706433/ → 127.0.0.1
  • http://2852039166/ → 169.254.169.254 (cloud metadata)
  • http://0x7f000001/, http://017700000001/, http://0/

When a template passes an untrusted or data-derived URL to resources.GetRemote and the host platform uses the cgo system resolver, these encodings resolve to the blocked address — allowing build-time server-side requests to loopback and internal services, including the cloud-metadata endpoint in hosted/CI builds. The same check is reused on redirects, so the gap also applies to each redirect hop.

This affects sites that rely on security.http.urls as a security boundary while fetching attacker-influenced remote URLs; it does not affect sites that fully trust the URLs they fetch.

References

  • github.com/advisories/GHSA-r46f-3rpw-hxrv
  • github.com/gohugoio/hugo/security/advisories/GHSA-r46f-3rpw-hxrv

Code Behaviors & Features

Detect and mitigate GHSA-r46f-3rpw-hxrv with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.162.0 before 0.163.1

Fixed versions

  • 0.163.1

Solution

Upgrade to version 0.163.1 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

go/github.com/gohugoio/hugo/GHSA-r46f-3rpw-hxrv.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:23:31 +0000.