GHSA-p8hv-x2cr-398fHighCVSS 7.5

OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals...

Published
August 16, 2026
Last Modified
August 16, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of sensitive values in these contexts.

🔗 References (4)