Go-slug
This hub aggregates every CVE we track for Go-slug, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
0
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2MEDIUM1
Monthly trend
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
2024-102026-09
Latest CVEs
The 3 most recently published vulnerabilities affecting Go-slug.
- CVE-2026-14978Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions5.5
- CVE-2025-0377HashiCorp go-slug Vulnerable to Zip Slip Attack7.5
- CVE-2020-29529HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fix...7.5
Product normalization is registry-driven with AI assist and human review. How it works