PT-2026-78711 · Hashicorp+1 · Go-Slug

·

CVE-2026-14978

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp go-slug versions 0.4.0 through 0.18.2
Description Improper handling of Unicode normalization during path matching allows a local attacker to bypass .terraformignore exclusions. This can result in sensitive files being included in Terraform slug uploads.
Recommendations Update HashiCorp go-slug to a version later than 0.18.2.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14978

Affected Products

Go-Slug