SECURITY ADVISORIES:
- When interacting with OCI Distribution registries for module or provider package installation, earlier versions of OpenTofu could incorrectly resend credentials intended for the original origin to the target of an HTTP redirect. (#4422)
- When interacting with an attacker-controlled remote state backend or provider/module registry,
tofu initin earlier versions of OpenTofu could potentially cause high CPU usage and/or high memory usage resolving crafted relative URLs in the API responses. (#4472)
Full Changelog: v1.12.5...v1.12.6