Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-71494— Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname

Quick assessment

Affected
infracost infracost
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Infracost 为工程师、AI 编码代理以及 CI/CD 系统提供云成本智能服务。在版本 0.10.45 之前,文件 以及相关的 Terraform Cloud、remote-plan 和 Terragrunt 注册表请求路径,可能会将配置好的 Terraform Cloud 或注册表令牌附加到一个从不可信的 Terraform 输入中推导出的目标主机名上,而未验证该主机名是否为配置中受信任的主机。当 CI 流水线在扫描攻击者可控的 Terraform 代码(例如使用 事件或在同一仓库内发起的拉取请求)时,若提

CVSS 5.9 · Medium EPSS 0.37% · P30

Affected Version Matrix 1

VendorProduct Version RangeStatus
infracost infracost < 0.10.45 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-71494

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname
Source: CVE Program / CVE List V5
Vulnerability Description
Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request paths can attach a configured Terraform Cloud or registry token to a destination hostname derived from untrusted Terraform input without confirming that it is the configured trusted host. When a CI run provides a token while scanning attacker-controlled Terraform, including pull_request_target or a same-repository pull request, an attacker can direct the request to an attacker-controlled host and disclose the token. Standard fork pull_request workflows without secrets are not exposed. This issue is fixed in version 0.10.45.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的凭证保护机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
infracost infracost < 0.10.45 -

II. Public POCs for CVE-2026-71494

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-71494

登录查看更多情报信息。

Patches & Fixes for CVE-2026-71494 (1)

Vendor Advisories for CVE-2026-71494 (1)

Vendor Pages for CVE-2026-71494 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-71494

No comments yet


Leave a comment