ZeroHour

CVE-2026-14978

CVSS 3.1
5.5 medium
EPSS
<1%p1
Published
()
Modified
Description

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.

Vendors
hashicorp
Products
go-slug
Weakness
CWE-176
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.