Denial of Service Vulnerability in OpenTofu by OpenTofu
CVE-2026-74797

2.3LOW

Key Information:

Vendor

Opentofu

Status
Vendor
CVE Published:
16 August 2026

What is CVE-2026-74797?

OpenTofu versions prior to 1.11.4 are susceptible to a denial of service vulnerability that arises from the processing of maliciously crafted .zip archives during the execution of the tofu init command. Attackers can exploit this vulnerability by manipulating the content of .zip archives used for dependency installation, which can lead to excessive CPU usage. This degradation in system performance may hinder the timely completion of the initialization process, thereby impacting overall functionality and user experience.

Affected Version(s)

opentofu 0 < 1.11.4

opentofu 1.11.4

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.