Go Slug HashiCorp Go Slug

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in HashiCorp Go Slug.

By the Year

In 2026 there have been 1 vulnerability in HashiCorp Go Slug with an average score of 5.5 out of ten. Go Slug did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 1 5.50
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 1 7.50

It may take a day or so for new Go Slug vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent HashiCorp Go Slug Security Vulnerabilities

HashiCorp go-slug 0.4.00.18.2 Unicode Normalization .terraformignore Bypass
CVE-2026-14978 5.5 - Medium - August 19, 2026

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.

Improper Handling of Unicode Encoding

HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives
CVE-2020-29529 7.5 - High - December 03, 2020

HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.

insecure temporary file

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for HashiCorp Go Slug or by HashiCorp? Click the Watch button to subscribe.

HashiCorp
Vendor

subscribe