<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Opentofu on CuraDevOps</title><link>https://curadevops.metacog.co.kr/tags/opentofu/</link><description>Recent content in Opentofu on CuraDevOps</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 24 Aug 2026 12:43:44 +0000</lastBuildDate><atom:link href="https://curadevops.metacog.co.kr/tags/opentofu/index.xml" rel="self" type="application/rss+xml"/><item><title>OpenTofu 1.12.6 patches credential-leak and DoS vulnerabilities</title><link>https://curadevops.metacog.co.kr/insights/2026-08-24-v1-12-6/</link><pubDate>Mon, 24 Aug 2026 12:43:44 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-24-v1-12-6/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Two security fixes affect IaC workflows: credentials intended for an OCI registry origin can leak to HTTP redirect targets, and tofu init can be forced into high CPU/memory usage via crafted URLs from an attacker-controlled state backend or registry. Upgrade OpenTofu to 1.12.6 in your IaC toolchain this sprint; no KEV listing or confirmed active exploitation, but both issues are directly triggerable in adversarial environments.&lt;/li>
&lt;li>&lt;strong>CI/CD — Plan:&lt;/strong> If tofu init runs in your pipelines against external module/provider registries or remote state backends, both the credential-leak and resource-exhaustion issues apply there too. Pin the OpenTofu version in your pipeline tooling to 1.12.6 as part of your next dependency update cycle.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>OpenTofu v1.11.14: final 1.11 patch fixes credential-leak and DoS CVEs</title><link>https://curadevops.metacog.co.kr/insights/2026-08-24-v1-11-14/</link><pubDate>Mon, 24 Aug 2026 12:43:44 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-24-v1-11-14/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Act:&lt;/strong> OpenTofu 1.11 hit EOL on 2026-08-19 and this is its final patch; the credential-leak via OCI HTTP redirect and the DoS via crafted remote-state URLs are both active security risks in IaC runs. Upgrade to a supported OpenTofu release series (1.12+) now that EOL has passed.&lt;/li>
&lt;li>&lt;strong>CI/CD — Act:&lt;/strong> The credential-leak bug affects &lt;code>tofu init&lt;/code> when pulling modules or providers from OCI registries — a standard pipeline step — and could expose registry credentials to a redirect target. Upgrade the OpenTofu version pinned in CI pipelines from 1.11.x to a supported series immediately; 1.11 is already EOL.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> OpenTofu 1.11 is past EOL (2026-08-19, 5d ago)&lt;/li>
&lt;/ul></description></item><item><title>OpenTofu v1.11.13 patches ECH key-identity leak</title><link>https://curadevops.metacog.co.kr/insights/2026-07-27-v1-11-13/</link><pubDate>Mon, 27 Jul 2026 14:28:32 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-27-v1-11-13/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> A security fix for an ECH pre-shared key identity leak in OpenTofu v1.11.x warrants upgrading to v1.11.13; no KEV listing or active exploitation reported, so this is a planned patch rather than an emergency — schedule the upgrade this sprint.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>OpenTofu v1.12.5: ECH privacy-leak security fix and provider-state bug fix</title><link>https://curadevops.metacog.co.kr/insights/2026-07-27-v1-12-5/</link><pubDate>Mon, 27 Jul 2026 14:28:32 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-27-v1-12-5/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Platform engineers running OpenTofu should upgrade to 1.12.5 to address the ECH handshake privacy leak (server hostname de-anonymization via passive observation) and the implicit-move provider state bug; no KEV listing or active exploitation reported, so no hard deadline, but this should be included in the next IaC toolchain update cycle.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Oracle migrates from Terraform to OpenTofu</title><link>https://curadevops.metacog.co.kr/insights/2026-07-21-oracle-dumps-terraform-for-opentofu/</link><pubDate>Tue, 21 Jul 2026 12:20:39 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-21-oracle-dumps-terraform-for-opentofu/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Oracle&amp;rsquo;s enterprise-scale migration validates OpenTofu as production-ready; teams running Terraform under the BUSL license should schedule an evaluation of OpenTofu as a drop-in replacement within the next planning cycle.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A major cloud vendor publicly switching to the OpenTofu fork is a clear signal that the fork has enterprise momentum; leaders standardized on Terraform should put an OpenTofu migration evaluation on the roadmap to reduce BUSL licensing risk before it becomes a contractual concern.&lt;/li>
&lt;/ul></description></item></channel></rss>