CVE-2026-74797: OpenTofu before 1.11.4 Denial of Service via malicious zip
OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenTofuto a version that resolves this vulnerability.Fixed in 1.11.4 - Compensating control
If you are using tofu init in an environment where provider/module .zip archives could be attacker-controlled, ensure only trusted, verified archives are used for dependency installation until you upgrade to OpenTofu 1.11.4.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74797?
The severity of CVE-2026-74797 is classified as low, with a score of 3.1.
How do I fix CVE-2026-74797?
To mitigate CVE-2026-74797, upgrade OpenTofu to version 1.11.4 or later.
What type of vulnerability is CVE-2026-74797?
CVE-2026-74797 is a denial of service vulnerability affecting OpenTofu.
What products are affected by CVE-2026-74797?
CVE-2026-74797 affects OpenTofu versions prior to 1.11.4.
Can CVE-2026-74797 be exploited remotely?
Yes, CVE-2026-74797 can be exploited remotely through the processing of malicious .zip archives.