HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.
Advisories
No advisories yet.
Fixes
Solution
Customers should evaluate the risk associated with this issue and consider upgrading to github.com/hashicorp/go-slug v0.18.3.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7284170 |
|
History
Wed, 19 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching. | |
| Title | Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions | |
| First Time appeared |
Hashicorp
Hashicorp go Slug |
|
| Weaknesses | CWE-176 | |
| CPEs | cpe:2.3:a:hashicorp:go_slug:0.18.2:*:*:*:*:*:*:* cpe:2.3:a:hashicorp:go_slug:0.4.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Hashicorp
Hashicorp go Slug |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-08-19T21:08:16.154Z
Reserved: 2026-07-07T16:52:26.760Z
Link: CVE-2026-14978
No data.
Status : Received
Published: 2026-08-19T21:16:54.007
Modified: 2026-08-19T21:16:54.007
Link: CVE-2026-14978
No data.
OpenCVE Enrichment
No data.
Weaknesses