CuraDevOps

Plan archived

OpenTofu v1.12.5: ECH privacy-leak security fix and provider-state bug fix

2026-07-27 14:28 UTC · Releases: opentofu · read the source ↗ #opentofu#security-patch#iac
  • Platform/SRE — Plan: Platform engineers running OpenTofu should upgrade to 1.12.5 to address the ECH handshake privacy leak (server hostname de-anonymization via passive observation) and the implicit-move provider state bug; no KEV listing or active exploitation reported, so no hard deadline, but this should be included in the next IaC toolchain update cycle.
  • CI/CD — Skip
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.