Denial of Service Vulnerability in OpenTofu by OpenTofu
CVE-2026-74797
2.3LOW
What is CVE-2026-74797?
OpenTofu versions prior to 1.11.4 are susceptible to a denial of service vulnerability that arises from the processing of maliciously crafted .zip archives during the execution of the tofu init command. Attackers can exploit this vulnerability by manipulating the content of .zip archives used for dependency installation, which can lead to excessive CPU usage. This degradation in system performance may hinder the timely completion of the initialization process, thereby impacting overall functionality and user experience.
Affected Version(s)
opentofu 0 < 1.11.4
opentofu 1.11.4
