{"api_version":"v1","generated_at":"2026-10-09T01:20:00+00:00","product":{"cve_count":21,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-gohugoio-hugo-3e6263df99df","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"hugo","next_cursor":null,"observations":[{"affected":"hugo: 0.56.0 < 0.166.0","affected_versions_present":true,"cve_id":"CVE-2026-100694","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100694","fixed":"hugo: 0.166.0","last_modified":"2026-09-30T15:05:16.280Z","patch_url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-pq74-mj4h-cjq2","primary_source":"","published":"2026-09-26T13:23:52.256Z"},{"affected":"hugo: 0.162.0 < 0.166.0","affected_versions_present":true,"cve_id":"CVE-2026-100693","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100693","fixed":"hugo: 0.166.0","last_modified":"2026-09-30T17:05:28.149Z","patch_url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-pmrv-x7gp-2rjw","primary_source":"","published":"2026-09-26T13:23:51.556Z"},{"affected":"hugo: < 0.166.0","affected_versions_present":true,"cve_id":"CVE-2026-100692","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100692","fixed":"hugo: 0.166.0","last_modified":"2026-09-28T16:30:24.018Z","patch_url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-797m-7j5g-3rpr","primary_source":"","published":"2026-09-26T13:23:50.847Z"},{"affected":"hugo: 0.75.0 < 0.166.0","affected_versions_present":true,"cve_id":"CVE-2026-100691","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100691","fixed":"hugo: 0.166.0","last_modified":"2026-09-28T17:51:34.652Z","patch_url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-q4xf-287f-98r8","primary_source":"","published":"2026-09-26T13:23:50.149Z"},{"affected":"hugo: 0.161.0 < 0.166.0","affected_versions_present":true,"cve_id":"CVE-2026-100690","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100690","fixed":"hugo: 0.166.0","last_modified":"2026-09-30T15:04:40.978Z","patch_url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-x3mx-cm49-8m9c","primary_source":"","published":"2026-09-26T13:23:49.448Z"},{"affected":"hugo: < 0.165.0","affected_versions_present":true,"cve_id":"CVE-2026-89259","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-89259","fixed":"hugo: 0.165.0","last_modified":"2026-09-11T20:29:43.170Z","patch_url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-vrm6-x8vp-mv2r","primary_source":"","published":"2026-09-11T11:15:35.062Z"},{"affected":"< 0.165.0","affected_versions_present":true,"cve_id":"CVE-2026-89258","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-89258","fixed":"0.165.0","last_modified":"2026-09-11T12:18:15.839Z","patch_url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-vrv5-r5rf-6v4j","primary_source":"","published":"2026-09-11T11:15:34.357Z"},{"affected":"hugo: 0.93.0 \u2264 0.165.0","affected_versions_present":true,"cve_id":"CVE-2026-10618","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-10618","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-26T18:20:58.149Z","patch_url":"","primary_source":"","published":"2026-08-24T10:29:10.191Z"},{"affected":"hugo: 0.91.0 \u2264 0.165.0","affected_versions_present":true,"cve_id":"CVE-2026-10582","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-10582","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/","last_modified":"2026-08-24T18:59:36.842Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-10582","primary_source":"","published":"2026-08-24T10:29:09.560Z"},{"affected":"hugo: 0.162.0 < 0.165.0","affected_versions_present":true,"cve_id":"CVE-2026-75926","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75926","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-09-24T14:19:33.478Z","patch_url":"https://github.com/gohugoio/hugo/commit/8a55df7af2e6da31297245cc54fa2e3b521d93e8","primary_source":"","published":"2026-08-18T15:47:49.048Z"},{"affected":">= 0.123.0, < 0.162.0","affected_versions_present":true,"cve_id":"CVE-2026-50135","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50135","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-07T16:57:29.874Z","patch_url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-fw87-fv5r-9fpw","primary_source":"","published":"2026-07-06T19:52:04.561Z"},{"affected":">= 0.91.0, < 0.162.0","affected_versions_present":true,"cve_id":"CVE-2026-50134","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50134","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-07T16:57:36.713Z","patch_url":"https://github.com/gohugoio/hugo/commit/86fbb0f7a8bbb93e2e916390de9e5a4f24bf9f50","primary_source":"","published":"2026-07-06T19:42:49.280Z"},{"affected":"< 0.162.0","affected_versions_present":true,"cve_id":"CVE-2026-50133","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50133","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-07T14:44:31.886Z","patch_url":"https://github.com/gohugoio/hugo/commit/e41a06447daa3071a01f333fdcec0a5153c3c8d1","primary_source":"","published":"2026-07-06T19:31:18.386Z"},{"affected":">= 0.123.0, < 0.163.1","affected_versions_present":true,"cve_id":"CVE-2026-58403","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-58403","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-06T20:51:27.624Z","patch_url":"https://github.com/gohugoio/hugo/commit/cf9c8f93ca2a2838ce378f9e36d052ac2f79e229","primary_source":"","published":"2026-07-06T19:25:45.971Z"},{"affected":">= 0.60.0, < 0.163.3","affected_versions_present":true,"cve_id":"CVE-2026-58402","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-58402","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-06T20:54:38.775Z","patch_url":"https://github.com/gohugoio/hugo/commit/ce1a7e0bce3713af40496ded3c2c0ceeed49231d","primary_source":"","published":"2026-07-06T19:19:58.754Z"},{"affected":">= v0.162.0, < v0.163.1","affected_versions_present":true,"cve_id":"CVE-2026-58404","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-58404","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-07T15:08:53.514Z","patch_url":"https://github.com/gohugoio/hugo/commit/a00b5c72ac57afe26df6688ece3ca544a56df372","primary_source":"","published":"2026-07-06T19:16:15.945Z"},{"affected":">= 0.43.0, < 0.161.0","affected_versions_present":true,"cve_id":"CVE-2026-44301","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44301","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-13T12:13:13.152Z","patch_url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-x597-9fr4-5857","primary_source":"","published":"2026-05-12T21:37:52.825Z"},{"affected":">= 0.60.0, < 0.159.2","affected_versions_present":true,"cve_id":"CVE-2026-35166","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35166","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-06T18:02:37.432Z","patch_url":"","primary_source":"","published":"2026-04-06T17:37:05.643Z"},{"affected":">= 0.123.0, < 0.139.4","affected_versions_present":true,"cve_id":"CVE-2024-55601","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-55601","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-10T17:13:48.519Z","patch_url":"","primary_source":"","published":"2024-12-09T21:11:10.463Z"},{"affected":">= 0.123.0, < 0.125.3","affected_versions_present":true,"cve_id":"CVE-2024-32875","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-32875","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-02T02:20:35.602Z","patch_url":"","primary_source":"","published":"2024-04-23T20:23:42.535Z"},{"affected":"< 0.79.1","affected_versions_present":true,"cve_id":"CVE-2020-26284","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-26284","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T15:56:03.976Z","patch_url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-8j34-9876-pvfq","primary_source":"","published":"2020-12-21T22:40:15.000Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"gohugoio"}}
