CVE-2026-14978
EUVD-2026-6309919.08.2026, 21:16
HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| hashicorp | go-slug | 0.4.0 ≤ 𝑥 ≤ 0.18.2 | CNA |
Common Weakness Enumeration