CVE-2026-14978

Source
https://cve.org/CVERecord?id=CVE-2026-14978
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14978.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-14978
Downstream
Related
Published
2026-08-19T21:16:54Z
Modified
2026-09-06T08:07:50Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.

References

Affected packages

Git / github.com/hashicorp/go-slug

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/go-slug
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:hashicorp:go-slug:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0.4.0"
        },
        {
            "fixed": "0.18.3"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v0.*
v0.10.0
v0.10.1
v0.11.0
v0.11.1
v0.12.0
v0.12.1
v0.12.2
v0.13.0
v0.13.1
v0.13.2
v0.13.3
v0.13.4
v0.14.0
v0.15.0
v0.15.1
v0.15.2
v0.16.0
v0.16.1
v0.16.2
v0.16.3
v0.16.4
v0.16.5
v0.16.6
v0.16.7
v0.16.8
v0.17.0
v0.17.1
v0.18.0
v0.18.1
v0.18.2
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.8.1
v0.9.0
v0.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14978.json"