CVE-2026-71494 | Infracost up to 0.10.44 Remote Variables Loader remote_variables_loader.go information disclosure
A vulnerability was found in Infracost up to 0.10.44 and classified as problematic. This affects an unknown function of the file internal/hcl/remote_variables_loader.go of the component Remote Variables Loader. Such manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2026-71494. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More