
🚨*CVE* CVE-2026-74797 OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or m… https://www.cve.org/CVERecord?id=CVE-2026-74797 ----- Traducción: CVE-2026-74797 Ope… https://infoflow.cloud`
Post summary
CVE-2026-74797 is a denial‑of‑service vulnerability in OpenTofu versions prior to 1.11.4, caused by malicious .zip archives processed by the tofu init command; no PoC, exploit, patch, or in‑the‑wild activity is detailed.

