v1.12.5
SECURITY ADVISORIES: Previous releases in the v1.12 series could be affected by several vulnerabilities: The Encrypted Client Hello implementation (which is used by OpenTofu through the go stdlib) would leak the pre-shared key identities during the handshake, allowing a passive network observer who can collect handshakes to de-anonymize the hostname of the server, even when ECH was being used. Thi…