CVE-2026-14978CWE-176

CVE-2026-14978

Medium · published August 20, 2026

CVSS v3.1
5.5
EPSS
0%
Percentile
2.2
In the wild
Unconfirmed
What it is

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.

The record
Technical detail
CVSS v3.1
5.5 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00121 · 2.2th percentile
Weakness
CWE-176 · Improper Handling of Unicode Encoding
Published
2026-08-20T01:16Z
Affected products (1)
ProductVersionsFixed in
hashicorp/go-slug≥ 0.4.0, < 0.18.30.18.3
References (1)
EPSS history
Timeline
  • 19 AUG 21:08Z
    Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions
    cvelistv5