Hashicorp · Go-Slug · CVE-2026-14978
**Name of the Vulnerable Software and Affected Versions**
HashiCorp go-slug versions 0.4.0 through 0.18.2
**Description**
Improper handling of Unicode normalization during path matching allows a local attacker to bypass `.terraformignore` exclusions. This can result in sensitive files being included in Terraform slug uploads.
**Recommendations**
Update HashiCorp go-slug to a version later than 0.18.2.