CVE-2026-74797
Received Received - Intake

Denial of Service in OpenTofu via Malicious ZIP Archives

Vulnerability report for CVE-2026-74797, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-16

Last updated on: 2026-08-16

Assigner: VulnCheck

Description

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-16
Last Modified
2026-08-16
Generated
2026-08-16
AI Q&A
2026-08-16
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
opentofu opentofu to 1.11.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial of service vulnerability in OpenTofu versions before 1.11.4. It occurs when the 'tofu init' command processes specially crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling the content of these .zip files during dependency installation, which degrades system performance and may prevent the init process from completing.

Detection Guidance

Monitor CPU usage during 'tofu init' commands. Check for processes consuming excessive CPU when processing .zip archives. Review logs for failed or hanging init commands.

Impact Analysis

The vulnerability can degrade system performance due to high CPU usage during the 'tofu init' process. It may cause delays or prevent the init command from completing, impacting development workflows. However, it requires user interaction to add a dependency from an untrusted source and does not allow arbitrary code execution or data disclosure.

Compliance Impact

This vulnerability primarily causes denial of service by consuming excessive CPU resources during dependency installation, which may delay or prevent system operations. It does not directly impact data confidentiality or integrity, so it likely has minimal direct effect on GDPR or HIPAA compliance unless system downtime disrupts regulated processes.

Mitigation Strategies

Upgrade OpenTofu to version 1.11.4 or later. Avoid adding dependencies from untrusted sources. Manually review and fetch artifacts externally if immediate upgrade is not possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74797. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart