Hugo does not properly escape some Markdown links
Published Apr 6, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.23%
Description
Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected. This vulnerability is fixed in 0.159.2.
Affected products
-
- Version >= 0.60.0, < 0.159.2StatusaffectedConstraints-
- Version
No data.
Red Hat Hardened Images
hugo-main-0.160.1-2.hum1
Fixed · RHSA-2026:7848
Red Hat Build of Kueue
kueue/kueue-must-gather-rhel9
Fix deferred
Red Hat Build of Kueue
kueue/kueue-operator-bundle
Fix deferred
Red Hat Build of Kueue
kueue/kueue-rhel9
Fix deferred
Red Hat Build of Kueue
kueue/kueue-rhel9-operator
Fix deferred
Red Hat OpenShift GitOps
openshift-gitops-1/argocd-rhel8
Fix deferred
Red Hat OpenShift GitOps
openshift-gitops-1/argocd-rhel9
Fix deferred
Red Hat OpenStack Platform 18.0
rhoso-operators/openstack-operator-bundle
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | hugo-main-0.160.1-2.hum1 | Fixed | RHSA-2026:7848 |
| Red Hat Build of Kueue | kueue/kueue-must-gather-rhel9 | Fix deferred | n/a |
| Red Hat Build of Kueue | kueue/kueue-operator-bundle | Fix deferred | n/a |
| Red Hat Build of Kueue | kueue/kueue-rhel9 | Fix deferred | n/a |
| Red Hat Build of Kueue | kueue/kueue-rhel9-operator | Fix deferred | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel9 | Fix deferred | n/a |
| Red Hat OpenStack Platform 18.0 | rhoso-operators/openstack-operator-bundle | Fix deferred | n/a |
github.com/gohugoio/hugo
Go
Introduced 0.60.0 Fixed 0.159.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/gohugoio/hugo | 0.60.0 | 0.159.2 |
Remediation
Red Hat mitigation
To mitigate this issue, ensure that all markdown content processed by Hugo originates from trusted sources. Alternatively, implement custom render hooks for links and images within Hugo to ensure proper escaping, as this configuration prevents exploitation.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 6, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Apr–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.23% (0.00233) | 12.91th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.18% (0.00185) | 8.25th | v5 (v2026.06.15) |
| Apr 7, 2026 | 0.05% (0.00047) | 14.49th | v4 (v2025.03.14) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-35166 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2455512 Issue Tracking
- https://github.com/advisories/GHSA-mcv8-8m8x-48pg Advisory
- https://github.com/gohugoio/hugo/commit/479fe6c654937a850b65e74551dc4e857d52898f
- https://github.com/gohugoio/hugo/security/advisories/GHSA-mcv8-8m8x-48pg x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-35166
- https://www.cve.org/CVERecord?id=CVE-2026-35166
Change history (0)
No recorded changes yet.