v1.12.7
SECURITY ADVISORIES: When using either a remote-exec or file provisioner to connect to an attacker-controlled SSH server, the server could previously deadlock the connection by sending certain unexpected packet types. (#4551) This addresses the upstream Go security advisories CVE-2026-78662 and CVE-2026-56855.