๐Ÿ” CVE Alert

CVE-2026-71494

UNKNOWN 0.0

Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request paths can attach a configured Terraform Cloud or registry token to a destination hostname derived from untrusted Terraform input without confirming that it is the configured trusted host. When a CI run provides a token while scanning attacker-controlled Terraform, including pull_request_target or a same-repository pull request, an attacker can direct the request to an attacker-controlled host and disclose the token. Standard fork pull_request workflows without secrets are not exposed. This issue is fixed in version 0.10.45.

CWE CWE-522
Vendor infracost
Product infracost
Published Aug 21, 2026
Last Updated Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for infracost infracost

Be the first to know when new unknown vulnerabilities affecting infracost infracost are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

infracost / infracost
< 0.10.45

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/infracost/infracost/security/advisories/GHSA-6x6c-w9w9-hv4h github.com: https://github.com/infracost/infracost/pull/3590 github.com: https://github.com/infracost/infracost/commit/3d24c757f5e4e60c7259f1b89ad7ceaabcfca86f github.com: https://github.com/infracost/infracost/releases/tag/v0.10.45