Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-74797

Опубликовано: 16 авг. 2026
Источник: redhat
CVSS3: 3.1

Описание

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.

A flaw was found in OpenTofu. A remote attacker could exploit this vulnerability by providing maliciously-crafted .zip archives during the tofu init command, which is used for provider or module package initialization. This could lead to excessive CPU usage, causing a Denial of Service (DoS) by degrading system performance and preventing the completion of the initialization process.

Отчет

This Low impact denial of service vulnerability in OpenTofu affects the tofu init command when processing maliciously-crafted .zip archives. Exploitation requires an attacker to provide a malicious archive, necessitating user interaction or a compromised dependency supply chain, which limits the attack surface in Red Hat environments where tofu init is typically executed in controlled development or CI/CD pipelines.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imageshi/opentofuNot affected
Red Hat Hardened Imagesopentofu1.10Not affected
Red Hat Hardened Imagesopentofu1.11Not affected
Red Hat Hardened Imagesopentofu1.12Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2517222github.com/opentofu/opentofu: OpenTofu: Denial of Service via malicious zip archives

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
nvd
16 дней назад

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.

CVSS3: 3.1
debian
16 дней назад

OpenTofu versions before 1.11.4 contain a denial of service vulnerabil ...

CVSS3: 3.1
github
16 дней назад

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.

3.1 Low

CVSS3