---
title: "Release v0.163.1 · gohugoio/hugo"
url: https://daily.dev/posts/release-v0-163-1-gohugoio-hugo-8arc16a1i
source_url: https://github.com/gohugoio/hugo/releases/tag/v0.163.1
type: article
source: "Hugo"
published: 2026-06-11T17:53:52.479Z
updated: 2026-06-11T17:54:15.516Z
tags: ["security", "golang"]
reading_time: 2
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Release v0.163.1 · gohugoio/hugo

**[Hugo](https://daily.dev/sources/hugo)** · 2 min read · 0 upvotes · 0 comments

## Summary

Hugo v0.163.1 is a security-focused patch release. The majority of fixes address security issues, including an upstream fix in golang.org/x/image (bumped from 0.41.0 to 0.42.0), normalization of integer IPv4 host encodings in HTTP URL checks, and dropping symlinks in several os.* functions to prevent path traversal-style issues. A bug fix for multi --renderSegments merge behavior and a convert command fix are also included. The maintainer notes an uptick in security reports driven by AI tools probing Hugo's security model, not a regression in Hugo's security posture.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://github.com/gohugoio/hugo/releases/tag/v0.163.1>

## Similar posts on daily.dev

- [Release v0.162.0 · gohugoio/hugo](https://daily.dev/posts/release-v0-162-0-gohugoio-hugo-egkcuot9a) · Hugo · 18 upvotes · 1 comments

---

Tags: [#security](https://daily.dev/tags/security), [#golang](https://daily.dev/tags/golang)

[View this post on daily.dev](https://daily.dev/posts/release-v0-163-1-gohugoio-hugo-8arc16a1i)
