CVE-2026-14978: Hashicorp Go-Slug
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.
Affected products
- Hashicorp Go-Slug: from 0.4.0, before 0.18.3 (fixed in 0.18.3)
Published 2026-08-19. Last modified 2026-09-04.