{"id":"GO-2026-5606","summary":"Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) in github.com/gohugoio/hugo","details":"Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) in github.com/gohugoio/hugo","aliases":["CVE-2026-58404","GHSA-r46f-3rpw-hxrv"],"modified":"2026-07-24T19:11:46.394705101Z","published":"2026-07-24T18:35:55Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-5606","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-r46f-3rpw-hxrv"},{"type":"FIX","url":"https://github.com/gohugoio/hugo/commit/a00b5c72ac57afe26df6688ece3ca544a56df372"}],"affected":[{"package":{"name":"github.com/gohugoio/hugo","ecosystem":"Go","purl":"pkg:golang/github.com/gohugoio/hugo"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.162.0"},{"fixed":"0.163.1"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/gohugoio/hugo/tpl/os","symbols":["Namespace.FileExists","Namespace.Stat"]},{"path":"github.com/gohugoio/hugo/config/security","symbols":["Config.CheckAllowedHTTPURL"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5606.json"}}],"schema_version":"1.7.5"}