-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 19 Sep 2026 22:05:30 +0200 Source: hugo Architecture: source Version: 0.166.0-1 Distribution: unstable Urgency: medium Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org> Changed-By: Dr. Tobias Quathamer <toddy@debian.org> Closes: 1146720 Changes: hugo (0.166.0-1) unstable; urgency=medium . * New upstream version 0.166.0 (Closes: #1146720) - Refresh patches - Ignore two tests due to internet connection - Build-Depend on golang-github-gobwas-glob-dev (>= 1.0.0) . - CVE-2026-10582 Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an integer, hex or octal IPv4 host, but it never resolves the hostname and never inspects the address the HTTP client actually connects to. The client constructed in resources/resource_factories/create/create.go installs no dial-time hook, so no check occurs at connection time either. A hostname that resolves to a loopback, private or cloud-metadata address therefore satisfies the policy, and the response body is embedded in the generated site. An attacker who can supply a URL through content, for example a front-matter field or a CMS field, can make the build fetch an internal endpoint and publish the response in the static output, so the build artifact itself carries the data out. . - CVE-2026-10618 Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value from a byte slice to a string as it is stored, deliberately dropping the escaping that used to happen there, and RenderAttributes in the same file escapes only values that are still byte slices, so its escaping branch is never reached and every value is written verbatim. The function's documentation states that it performs HTML escaping of string attributes, which it does not. A quote inside an attribute value in the info string therefore terminates the attribute and allows a further attribute, including an event handler, to be placed on the wrapper element, and the script runs for every visitor who loads the page. This path is reached under the default configuration, with code fences enabled and without goldmark's unsafe setting or any custom render hook. Attribute names beginning with on are filtered when the attributes are parsed, so injection is achieved through the value rather than the name. Checksums-Sha1: 3d5d9d32c9b13a56834cc9a7d82723b6e9842573 6569 hugo_0.166.0-1.dsc ce81c4813d2bb978a28f5666dd0407db220af9ba 9885828 hugo_0.166.0.orig.tar.xz ccc8606166f92e22d1ac66205176fd511a714887 609912 hugo_0.166.0-1.debian.tar.xz 5df0a141fea32e994646ba5bcd04f9cfba4018ef 15992240 hugo_0.166.0-1.git.tar.xz de03ac68ce721e741af14ef5a4d6349d74650e88 17718 hugo_0.166.0-1_source.buildinfo Checksums-Sha256: 158b526d6ea5a9ae8b7a8503610892440c7157b40d2755d8d8385736866f5a4f 6569 hugo_0.166.0-1.dsc 903d048049a55d7ebdee6ce2378c4a5322d51c5e72a213d83047485eab8a6e83 9885828 hugo_0.166.0.orig.tar.xz c96e4e9b501d81123b051deebc8afdb923dd2c69b6eef4e563176be7e493033c 609912 hugo_0.166.0-1.debian.tar.xz 6ac7cd0c30d4c61529417da7cfda43af2c10c74daecf49d7f1b2d0f528c1d711 15992240 hugo_0.166.0-1.git.tar.xz 90e79c9ca7656ef20cd904359096434100398e45ee81cb1790f95a27f1db92e2 17718 hugo_0.166.0-1_source.buildinfo Files: 482f730014c3e1aeb09e534d18c67a7f 6569 web optional hugo_0.166.0-1.dsc b36d6cc285144aa3a601c3be90617556 9885828 web optional hugo_0.166.0.orig.tar.xz 7f8fdcc60a08f4003b8eb31533a39815 609912 web optional hugo_0.166.0-1.debian.tar.xz a2b80bb98e1a2b5d59940d50fc009e8b 15992240 web None hugo_0.166.0-1.git.tar.xz 31e558c04b915d3a1949dfecd95735ed 17718 web optional hugo_0.166.0-1_source.buildinfo Git-Tag-Info: tag=6f86d39bb1289717eea8ef21f3f668db087ea599 fp=d1cb8f39bc5ded24c5d2c78c1302f1f036ebeb19 Git-Tag-Tagger: Dr. Tobias Quathamer <toddy@debian.org> -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqu7XYACgkQYG0ITkaD wHlAnxAAnqBD8D3MBP2OtdkH5CawmN9BaFIY4ymnbi9KMXtsFmUMIUo9AMCqqWdH dxpEER0HPMdHhjhQrJ7zvoThLGxUwW1eJqMiC4aywxXMn3BYS0W4X25xc6N1+EnD NhCFxKfKCTMszskWhrYtayR8JnCsHoQLaoZWlIeXuZpy/ccOYeB+dck1xC+z4CZL NOoSJ+OUVD7CkEU/Az9gEEiHp0tHiWteHWQvYp0h3eD5cbMrDXy1Ihvn71tUxZGF cYmLvVkG3QrVnxg9kE7ERAAYDlBVGAzWxVxaXbb+NXgIUCCcyNbo5gEAIKLWvvZP lRXrZDj1BlVbhjX81qYiI3J4sgNF3XNHGHvKSi6f2nELDubkGs7ZyqBAjhgu9d+6 VbVSTWPMmOd1p3BFW8g0Hy7wAXTKdKQ+8xGNr31HLO7ghkIZUZk8JC9HpnkFCNcr TY4gM8CH2292H/oP5nDXdkKxxsNla1q46CAA8Fh8Gyht9i06UehqMNUH+oa1/1o1 Exu+BVpKF2anDw84E/v/RXtNIYZGpwwFV3nvIqADHfm+wnftoC15eU7xsm+Lc95h Ocj8BJsoelYtdQGO9dvEWlCl1ojMuXSg6hNg1KzwY1AOpWh47msJhVShnjgB1W5v adZwYYghz6/FmTYLeWS1Q0hwF4ZXswcHK/MgQvXz+JmXAPyQ2XI= =KkPs -----END PGP SIGNATURE-----