[Git][security-tracker-team/security-tracker][master] Add three more hugo issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 7 09:39:25 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c5fbaa4d by Salvatore Bonaccorso at 2026-07-07T10:38:35+02:00
Add three more hugo issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -78,11 +78,17 @@ CVE-2026-53641 (FOSSBilling is a free, open-source billing and client management
 CVE-2026-53640 (FOSSBilling is a free, open-source billing and client management syste ...)
 	NOT-FOR-US: FOSSBilling
 CVE-2026-50135 (Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression ...)
-	TODO: check
+	- hugo 0.162.1-1
+	NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-fw87-fv5r-9fpw
+	NOTE: Fixed by: https://github.com/gohugoio/hugo/commit/f8b5fa09a64950c32b803821ede411ebfe772b7a (v0.162.0)
 CVE-2026-50134 (Hugo is a static site generator. From 0.91.0 until 0.162.0, resources. ...)
-	TODO: check
+	- hugo 0.162.1-1
+	NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-vxgm-5rmg-5w8g
+	NOTE: Fixed by: https://github.com/gohugoio/hugo/commit/86fbb0f7a8bbb93e2e916390de9e5a4f24bf9f50 (v0.162.0)
 CVE-2026-50133 (Hugo is a static site generator. Prior to 0.162.0, Hugo accepts conten ...)
-	TODO: check
+	- hugo 0.162.1-1
+	NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-c54g-xjwj-8g82
+	NOTE: Fixed by: https://github.com/gohugoio/hugo/commit/e41a06447daa3071a01f333fdcec0a5153c3c8d1 (v0.162.0)
 CVE-2026-4375 (The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPres ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-48267 (DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c5fbaa4d1e57b9fff3fdc21525695564519ab17c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c5fbaa4d1e57b9fff3fdc21525695564519ab17c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260707/ceb0e40d/attachment.htm>


More information about the debian-security-tracker-commits mailing list