Vulnerabilities
Vulnerable Software
Hashicorp:  >> Go-Slug  >> 0.16.2  Security Vulnerabilities
HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.
CVSS Score
5.5
EPSS Score
0.001
Published
2026-08-19
HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.
CVSS Score
7.5
EPSS Score
0.007
Published
2025-01-21


Contact Us

Shodan ® - All rights reserved