Security Advisory

CVE-2026-14978

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-19 21:08:16
Last updated 2026-08-20 15:20:13
Assigner ibm
CVSS score 5.5
State PUBLISHED

Description

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.