Description
HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.
No analysis available yet.
Remediation
Vendor Solution
Customers should evaluate the risk associated with this issue and consider upgrading to github.com/hashicorp/go-slug v0.18.3.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7284170 |
|
History
Wed, 19 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching. | |
| Title | Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions | |
| First Time appeared |
Hashicorp
Hashicorp go Slug |
|
| Weaknesses | CWE-176 | |
| CPEs | cpe:2.3:a:hashicorp:go_slug:0.18.2:*:*:*:*:*:*:* cpe:2.3:a:hashicorp:go_slug:0.4.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Hashicorp
Hashicorp go Slug |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-08-19T21:08:16.154Z
Reserved: 2026-07-07T16:52:26.760Z
Link: CVE-2026-14978
No data.
Status : Received
Published: 2026-08-19T21:16:54.007
Modified: 2026-08-19T21:16:54.007
Link: CVE-2026-14978
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-176
Improper Handling of Unicode Encoding