Security Advisory

CVE-2026-14978

5.5
MEDIUM

Vulnerability Description

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.
Published Date August 19, 2026
Official Source NIST NVD Advisory