Description
OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.
Published: 2026-08-16
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenTofu versions earlier than 1.11.4 process maliciously crafted .zip archives when running the tofu init command for provider or module packages. The extraction of these archives can cause excessive CPU usage, degrading system performance and preventing timely completion of the init process. The impact is a denial of service against the init operation, reducing availability of configuration processing for the affected environment.

Affected Systems

The vulnerability affects OpenTofu, specifically all releases prior to 1.11.4. Users running these older versions should verify their current version and consider an upgrade to avoid exposure.

Risk and Exploitability

The CVSS score of 2.3 classifies this flaw as low severity. EPSS is not available and the issue is not listed in the CISA KEV catalog. The attack requires that an adversary supply a malicious .zip archive during dependency installation, which is likely a local or supply‑chain vector. While the flaw does not provide remote code execution, the resulting denial of service can cause service interruption during deployment and build processes.

Generated by OpenCVE AI on August 16, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenTofu to version 1.11.4 or later to apply the fix.
  • Ensure that all provider or module archives are sourced from trusted repositories and verify archive integrity before extraction to prevent malicious content.
  • Run tofu init inside a sandboxed container with CPU limits to restrict resource consumption and isolate the process from the host system.
  • Monitor CPU usage during init and set alerts for abnormal spikes that may indicate an exploitation attempt.

Generated by OpenCVE AI on August 16, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 16 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Description OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.
Title OpenTofu before 1.11.4 Denial of Service via malicious zip
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-16T13:14:19.060Z

Reserved: 2026-08-16T12:59:42.223Z

Link: CVE-2026-74797

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-16T14:16:57.930

Modified: 2026-08-16T14:16:57.930

Link: CVE-2026-74797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-16T14:45:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption