CVE-2026-100693

Description

A flaw was found in Hugo. Case-sensitive validation in the URL deny rule mechanism allows an attacker to bypass access restrictions. By supplying mixed-case URL schemes when fetching remote resources, an attacker can access restricted network destinations, such as localhost or internal IP addresses. This may lead to unauthorized access to internal network services and information disclosure.

Statement

Red Hat Product Security rates this flaw Moderate. In historical Hummingbird Hugo builds, an untrusted URL passed to resources.GetRemote could bypass the default IP-literal deny rule by using a mixed-case scheme, allowing the build process to fetch restricted network resources. The current Hummingbird Hugo package contains the fix. Other identified product affects are not vulnerable because their Hugo dependency versions predate the flaw or the shipped Grafana packages do not execute Hugo.

Mitigation

Do not pass untrusted URLs to resources.GetRemote. Where remote fetching is required, configure security.http.urls with an explicit allowlist of trusted hosts.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score4N/A8.4
Attack VectorLocalN/ALocal
Attack ComplexityLowN/ALow
Privileges RequiredNoneN/ANone
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityLowN/AHigh
Integrity ImpactNoneN/AHigh
Availability ImpactNoneN/AHigh

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

cve.org: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Application Data

Integrity

Technical Impact: Execute Unauthorized Code or Commands

Access Control

Technical Impact: Bypass Protection Mechanism

By providing URLs to unexpected hosts or ports, attackers can make it appear that the server is sending the request, possibly bypassing access controls such as firewalls that prevent the attackers from accessing the URLs directly. The server can be used as a proxy to conduct port scanning of hosts in internal networks, use other URLs such as that can access documents on the system (using file://), or use other protocols such as gopher:// or tftp://, which may provide greater control over the contents of requests.

Frequently Asked Questions

Want to get errata notifications? Sign up here.