Infrastructure as code

OpenTofu: what changed

In the last 90 days, 14 summarized changes: 6 security advisories, 2 deprecations, 1 releases, 5 fixes. Stackdiff reads OpenTofu's own feeds (opentofu.org) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .

Needs attention

Breaking changes, security advisories, end-of-life and license changes from the last 90 days, worst first.

1.11.9Securityhigh
GO-2026-6262: OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentof
1.11.9Securityhigh
GHSA-22w5-2fxg-vrwx: OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
1.12.5Securitymedium
v1.12.5
1.11.13Securitymedium
v1.11.13
1.10.10Securitymedium
GO-2026-5705: OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree in github.com/opentofu/opentofu
1.10.10Securitymedium
GHSA-wcmj-x466-56mm: OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree

Latest changes

Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.

News
So you want to use OpenRouter?
News
GPT-6 Astra on OpenRouter
News
A Vision for Built-in Linting
1.13.0-beta1Deprecatedmedium
v1.13.0-beta1
1.11.9Securityhigh
GO-2026-6262: OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentof
1.11.9Securityhigh
GHSA-22w5-2fxg-vrwx: OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
1.12.6Release
v1.12.6
1.11.14Fix
v1.11.14
1.12.5Securitymedium
v1.12.5
1.11.13Securitymedium
v1.11.13
1.12.4Fix
v1.12.4
1.11.12Fix
v1.11.12
1.10.10Securitymedium
GO-2026-5705: OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree in github.com/opentofu/opentofu
1.10.10Securitymedium
GHSA-wcmj-x466-56mm: OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree
1.11.11Fix
v1.11.11
1.12.3Deprecatedmedium
v1.12.3
1.11.10Fix
v1.11.10
1.11.8Securityhigh
GHSA-pxh5-6rrc-8rjv: OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server
1.12.0News
OpenTofu v1.12.0
1.12.0-beta1News
OpenTofu 1.12.0-beta1 is now available
1.11.4Securityhigh
GO-2026-4352: OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip format in github.com/opentofu/opentofu
News
Machine and Human readable command output streams
1.11.4Securityhigh
GHSA-r92c-9c7f-3pj8: OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip format
1.11.0News
OpenTofu v1.11.0
1.10.7Securityhigh
GHSA-w2jf-268q-mrvh: OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responses
1.11.0-beta1Deprecatedmedium
Help us test OpenTofu 1.11.0-beta1
News
Fidelity Investments Shares Its Migration Story from Terraform to OpenTofu
News
Ephemeral Support in OpenTofu
1.10.0Deprecatedmedium
OpenTofu 1.10.0: A Well-Seasoned Release
1.10.0-beta1News
Help us test OpenTofu 1.10.0-beta1

Where Stackdiff reads OpenTofu

Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.

Get OpenTofu changes in your Monday brief

Add OpenTofu and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.

Get your first brief

Other infrastructure as code tools