The current version of OpenTofu is 1.13.1 (as of 01/10/2026). patchletter checks the official source daily and emails you new releases.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Golang Go: Mehrere Schwachstellen
WID-SEC-W-2025-2227 · 19 Aug
- OpenTofu: Mehrere Schwachstellen
WID-SEC-W-2026-2864 · 17 Aug
- OpenTofu: Schwachstelle ermöglicht Offenlegung von Informationen
WID-SEC-W-2026-2010 · 19 Jun
- OpenTofu: Schwachstelle ermöglicht Manipulation von Dateien
WID-SEC-W-2026-1642 · 22 May
OpenTofu at a glance
OpenTofu is an open-source infrastructure-as-code tool — a community-driven, Linux Foundation fork of Terraform created after its license change, and a drop-in alternative for many workflows. OpenTofu ships regular releases plus security fixes.
For admins OpenTofu behaves like Terraform: pin the CLI and provider versions for reproducible runs across the team and CI, and read the upgrade notes for state-format and provider changes before moving versions. The state file often contains secrets — keep it in a secured remote backend with locking. Compatibility with Terraform configurations is broad but diverges over time as each project adds features — check specifics when migrating or maintaining both. After upgrading, run a plan and review the diff before applying. Track your version and the project's support window; patchletter flags new OpenTofu releases.
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 1.13.1 | STABLE | 01/10/2026 | Release notes → |
| 1.13.0 | STABLE | 30/09/2026 | Release notes → |
| 1.12.6 | STABLE | 19/08/2026 | Release notes → |
| 1.12.5 | STABLE | 21/07/2026 | Release notes → |
| 1.12.4 | STABLE | 13/07/2026 | Release notes → |
| 1.12.3 | STABLE | 18/06/2026 | Release notes → |
| 1.12.2 | STABLE | 12/06/2026 | Release notes → |
| 1.12.1 | STABLE | 27/05/2026 | Release notes → |
| 1.12.0 | STABLE | 14/05/2026 | Release notes → |
| 1.11.13 | STABLE | 21/07/2026 | Release notes → |
| 1.11.12 | STABLE | 13/07/2026 | Release notes → |
| 1.11.11 | STABLE | 23/06/2026 | Release notes → |
| 1.11.10 | STABLE | 18/06/2026 | Release notes → |
| 1.11.9 | STABLE | 12/06/2026 | Release notes → |
| 1.11.8 | STABLE | 14/05/2026 | Release notes → |
| 1.11.7 | STABLE | 11/05/2026 | Release notes → |
| 1.11.6 | STABLE | 08/04/2026 | Release notes → |
| 1.11.5 | STABLE | 12/02/2026 | Release notes → |
| 1.11.4 | STABLE | 21/01/2026 | Release notes → |
| 1.11.3 | STABLE | 13/01/2026 | Release notes → |
| 1.11.2 | STABLE | 19/12/2025 | Release notes → |
| 1.11.1 | STABLE | 10/12/2025 | Release notes → |
| 1.11.0 | STABLE | 09/12/2025 | Release notes → |
| 1.10.10 | STABLE | 11/05/2026 | Release notes → |
| 1.10.9 | STABLE | 12/02/2026 | Release notes → |
| 1.10.8 | STABLE | 08/12/2025 | Release notes → |
Frequently asked questions
- What is the latest version of OpenTofu?
- OpenTofu 1.13.1, released 01/10/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the OpenTofu release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new OpenTofu updates?
- Tick OpenTofu off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new OpenTofu version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current OpenTofu version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/opentofu)https://patchletter.com/badge/opentofu.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).