CVE-2026-74797 LOW

CVE-2026-74797: OpenTofu before 1.11.4 Denial of Service via malicious zip

Vendor Opentofu
Product opentofu
Weakness CWE-400
Published August 16, 2026
Last update August 17, 2026

CVSS base score

2.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.

Key dates

02Disclosure timeline

August 16, 2026 CVE published
August 17, 2026 Record updated

Related vulnerabilities

04Related CVE