CVE-2026-14978
EUVD-2026-6309919.08.2026, 21:16
HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hashicorp | go-slug | 0.4.0 ≤ 𝑥 < 0.18.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration