CuraDevOps

Act active

OpenTofu v1.11.14: final 1.11 patch fixes credential-leak and DoS CVEs

2026-08-24 12:43 UTC · Releases: opentofu · read the source ↗ #opentofu#security#iac
  • Platform/SRE — Act: OpenTofu 1.11 hit EOL on 2026-08-19 and this is its final patch; the credential-leak via OCI HTTP redirect and the DoS via crafted remote-state URLs are both active security risks in IaC runs. Upgrade to a supported OpenTofu release series (1.12+) now that EOL has passed.
  • CI/CD — Act: The credential-leak bug affects tofu init when pulling modules or providers from OCI registries — a standard pipeline step — and could expose registry credentials to a redirect target. Upgrade the OpenTofu version pinned in CI pipelines from 1.11.x to a supported series immediately; 1.11 is already EOL.
  • Leader — Skip
  • Signals: OpenTofu 1.11 is past EOL (2026-08-19, 5d ago)
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.