
New CVE-2026-71494, token disclosure in Infracost (<0.10.45). Infracost attached your Terraform Cloud token to a request whose host came straight from the scanned .tf, with no check it was the real endpoint. Point the hostname at your server, receive the token. #cve #research https://t.co/GRFnjk49U8
Post summary
The tweet announces CVE‑2026‑71494, detailing how Infracost <0.10.45 can unintentionally disclose Terraform Cloud tokens, and outlines a proof‑of‑concept for capturing them by pointing the host to an attacker’s server.

