CVE-2026-14978

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.
References
Link Resource
https://www.ibm.com/support/pages/node/7284170 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:hashicorp:go-slug:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-19 21:16

Updated : 2026-09-04 16:54


NVD link : CVE-2026-14978

Mitre link : CVE-2026-14978

CVE.ORG link : CVE-2026-14978


JSON object : View

Products Affected

hashicorp

  • go-slug
CWE
CWE-176

Improper Handling of Unicode Encoding