Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4111 articles · 197511 vulns · 37/41 feeds (7d)
← Back to list
5.5
CVE-2026-14978PATCHED
hashi · go-slug

Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions

Description

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.

Affected Products

VendorProductVersions
hashigo-slug0.4.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
hashiterraformcert_advisory90%

References

  • https://www.ibm.com/support/pages/node/7284170(vendor-advisory, patch)

Related News (2 articles)

Tier B
BSI Advisories1d ago
[NEU] [mittel] Hashicorp Terraform: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Offenlegung von Informationen
→ No new info (linked only)
Tier C
VulDB6d ago
CVE-2026-14978 | HashiCorp go-slug up to 0.18.2 Unicode Normalization privileges management
→ No new info (linked only)
CVSS 3.15.5 MEDIUM
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.ibm.com/support/pages/node/7284170
CWECWE-176
PublishedAug 19, 2026
Trending Score29
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-16498
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
Trending: 11
HIGHCVE-2026-14869
terraform-mcp-server vulnerable to server side request forgery leading to token exposure
Trending: 10
HIGHCVE-2026-16496
terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
Trending: 9
HIGHCVE-2026-19589
Packer vulnerable to arbitrary file write via crafted plugin archive during installation
Trending: 8
HIGHCVE-2026-14886
Vault Enterprise vulnerable to cross-namespace entity deletion
Trending: 8

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 19, 2026
Discovered by ZDM
Aug 19, 2026
Patch Available
Aug 20, 2026