What is CVE-2026-14978?
CVE-2026-14978: A vulnerability in HashiCorp go-slug library allows local attackers to bypass .terraformignore exclusions and include sensitive files in Terraform slug uploads due to improper Unicode normalization during path matching. This affects versions 0.4.0 through 0.18.2, and updating the library is recommended.
Azərbaycanca: CVE-2026-14978: HashiCorp go-slug kitabxanasında Unicode normallaşdırma zəifliyi yerli təcavüzkara .terraformignore faylını keçərək həssas məlumatların Terraform slug yükləmələrinə daxil edilməsinə səbəb ola bilər. Bu, 0.4.0 ilə 0.18.2 arası versiyaları təsir edir və istifadəçilərə kitabxananı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What software is affected by CVE-2026-14978?
CVE-2026-14978 is a vulnerability found in the HashiCorp go-slug library affecting versions 0.4.0 through 0.18.2.
How to protect against the CVE-2026-14978 vulnerability?
It is recommended that users update the HashiCorp go-slug library.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.