CVE-2026-14978: Hashicorp Go-Slug

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.

Affected products

  • Hashicorp Go-Slug: from 0.4.0, before 0.18.3 (fixed in 0.18.3)

Published 2026-08-19. Last modified 2026-09-04.