Impact
OpenTofu versions earlier than 1.11.4 process maliciously crafted .zip archives when running the tofu init command for provider or module packages. The extraction of these archives can cause excessive CPU usage, degrading system performance and preventing timely completion of the init process. The impact is a denial of service against the init operation, reducing availability of configuration processing for the affected environment.
Affected Systems
The vulnerability affects OpenTofu, specifically all releases prior to 1.11.4. Users running these older versions should verify their current version and consider an upgrade to avoid exposure.
Risk and Exploitability
The CVSS score of 2.3 classifies this flaw as low severity. EPSS is not available and the issue is not listed in the CISA KEV catalog. The attack requires that an adversary supply a malicious .zip archive during dependency installation, which is likely a local or supply‑chain vector. While the flaw does not provide remote code execution, the resulting denial of service can cause service interruption during deployment and build processes.
OpenCVE Enrichment