Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (8)
📋 Description
CVE-2026-10582 — hugo: github.com/gohugoio/hugo: Hugo: Server-Side Request Forgery (SSRF) leading to information disclosure. CVE-2026-10618 — github.com/gohugoio/hugo: Hugo: Stored Cross-Site Scripting via unescaped code-fence attribute values CVE-2026-33812 — golang.org/x/image: golang.org/x/image: Denial of Service due to excessive memory allocation when parsing malicious font files CVE-2026-100690 — github.com/gohugoio/hugo: Hugo: Arbitrary file read via symbolic link sandbox escape CVE-2026-100691 — github.com/gohugoio/hugo: Hugo: Stored cross-site scripting via unescaped lineAnchors option CVE-2026-100692 — github.com/gohugoio/hugo: Hugo: Information disclosure via symlinked mount roots CVE-2026-100693 — github.com/gohugoio/hugo: Hugo: Security restriction bypass via mixed-case URL schemes CVE-2026-100694 — github.com/gohugoio/hugo: Hugo: Cross-site scripting via unescaped HTML in Org Mode content
🎯 Affected products4
- Red Hat Hardened Images
- hugo-0:0.166.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- hugo-0:0.166.0-0.1.hum1@src as a component of Red Hat Hardened Images
- hugo-0:0.166.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this vulnerability, ensure that the Hugo `security.http.urls` allowlist is strictly configured to permit outbound requests only to explicitly trusted external domains. Implement network egress filtering to prevent Hugo from initiating connections to internal, loopback, or private IP address ranges. This can be achieved by configuring firewall rules or network policies to block outbound traffic from the Hugo environment to RFC1918 addresses and other internal network segments. Workaround: Update to a fixed version of Hugo. As a workaround, disable code-fence attribute support in the goldmark configuration by setting markup.highlight.codeFences to false, or use a custom render hook that explicitly escapes attribute values before writing them to HTML output. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, implement the following operational controls: 1. Avoid processing untrusted pull requests, themes, or repository branches that execute Node.js transformation pipelines (such as PostCSS, TailwindCSS, or Babel). Builds that do not execute Node.js tools are unaffected. 2. Isolate Hugo builds inside dedicated containers or ephemeral sandboxes that have no sensitive host directories or files mounted, and run the build process with minimal privileges. Caveat: Disabling or avoiding Node.js asset transformations may prevent custom stylesheets or scripts from compiling properly, which can alter the appearance or functionality of the generated site. Workaround: Inspect checked-in themes and vendored modules for symlinks at mount roots before building. Build untrusted content in an isolated environment without access to sensitive host files. Workaround: Do not pass untrusted URLs to resources.GetRemote. Where remote fetching is required, configure security.http.urls with an explicit allowlist of trusted hosts. Workaround: There is no mitigation available for this issue. Red Hat recommends that customers update to the latest available version that contains the fix.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:66266
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-10618
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-10582
- externalhttps://access.redhat.com/security/cve/CVE-2026-44301
- externalhttps://access.redhat.com/security/cve/CVE-2026-33812
- externalhttps://access.redhat.com/security/cve/CVE-2026-100693
- externalhttps://access.redhat.com/security/cve/CVE-2026-100690
- externalhttps://access.redhat.com/security/cve/CVE-2026-100694
- externalhttps://access.redhat.com/security/cve/CVE-2026-100692
- externalhttps://access.redhat.com/security/cve/CVE-2026-100691
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_66266.json