PT-2026-73164 · Opentofu · Opentofu

CVE-2026-74797

·

Published

2026-01-21

·

Updated

2026-08-17

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenTofu versions prior to 1.11.4
Description A denial of service issue exists in the tofu init command when processing maliciously-crafted .zip archives used for provider or module packages. An attacker can control the content of the .zip archive served during dependency installation to cause excessive CPU usage, which degrades system performance and prevents the initialization process from completing.
Recommendations Update to version 1.11.4 or later.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74797
GHSA-R92C-9C7F-3PJ8
GO-2026-4352

Affected Products

Opentofu