Plan
active
OpenTofu 1.12.6 patches credential-leak and DoS vulnerabilities
- Platform/SRE — Plan: Two security fixes affect IaC workflows: credentials intended for an OCI registry origin can leak to HTTP redirect targets, and tofu init can be forced into high CPU/memory usage via crafted URLs from an attacker-controlled state backend or registry. Upgrade OpenTofu to 1.12.6 in your IaC toolchain this sprint; no KEV listing or confirmed active exploitation, but both issues are directly triggerable in adversarial environments.
- CI/CD — Plan: If tofu init runs in your pipelines against external module/provider registries or remote state backends, both the credential-leak and resource-exhaustion issues apply there too. Pin the OpenTofu version in your pipeline tooling to 1.12.6 as part of your next dependency update cycle.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.