Security Advisory
CVE-2026-14978
5.5
MEDIUM
Vulnerability Description
HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.
Published Date
August 19, 2026
Official Source
NIST NVD Advisory