Act
active
OpenTofu v1.11.14: final 1.11 patch fixes credential-leak and DoS CVEs
- Platform/SRE — Act: OpenTofu 1.11 hit EOL on 2026-08-19 and this is its final patch; the credential-leak via OCI HTTP redirect and the DoS via crafted remote-state URLs are both active security risks in IaC runs. Upgrade to a supported OpenTofu release series (1.12+) now that EOL has passed.
- CI/CD — Act: The credential-leak bug affects
tofu initwhen pulling modules or providers from OCI registries — a standard pipeline step — and could expose registry credentials to a redirect target. Upgrade the OpenTofu version pinned in CI pipelines from 1.11.x to a supported series immediately; 1.11 is already EOL. - Leader — Skip
- Signals: OpenTofu 1.11 is past EOL (2026-08-19, 5d ago)
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.