Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an integer, hex or octal IPv4 host, but it never resolves the hostname and never inspects the address the HTTP client actually connects to. The client constructed in resources/resource_factories/create/create.go installs no dial-time hook, so no check occurs at connection time either. A hostname that resolves to a loopback, private or cloud-metadata address therefore satisfies the policy, and the response body is embedded in the generated site. An attacker who can supply a URL through content, for example a front-matter field or a CMS field, can make the build fetch an internal endpoint and publish the response in the static output, so the build artifact itself carries the data out.
We have discovered 34,064 live websites that are affected by CVE-2026-10582.
| Product | |
| Category | Web Application Frameworks |
| Vulnerable Domains | 34,064 live websites (71% of Hugo install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 210 versions ( 64% of all versions) |
| 19,455 websites | |
| 4,305 websites | |
| 1,375 websites | |
| 1,029 websites | |
| 860 websites | |
| 641 websites | |
| 538 websites | |
| 442 websites | |
| 364 websites | |
| 362 websites |
| .com | 13,272 websites |
| .org | 2,657 websites |
| .de | 2,371 websites |
| .net | 2,321 websites |
| .io | 910 websites |
| .fr | 745 websites |
| .co.uk | 579 websites |
| .nl | 573 websites |
| .ca | 425 websites |
| .ch | 371 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.org | *** | ||
| ****.net | *,*** | ||
| ********.com | *,*** | ||
| *******.com | *,*** | ||
| ********.com | *,*** | ||
| ***********.org | *,*** | ||
| *********.io | *,*** | ||
| **********.org | *,*** | ||
| ******.io | *,*** | ||
| *******.org | *,*** |