CVE-2026-74797Disclosure

LOWCVSS 2.3 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-16: 2Patch / Workaround · 2026-08-16: 1Technical Details · 2026-08-16: 208-16
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-74797 OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or m… https://www.cve.org/CVERecord?id=CVE-2026-74797 ----- Traducción: CVE-2026-74797 Ope… https://infoflow.cloud`

    Post summary

    CVE-2026-74797 is a denial‑of‑service vulnerability in OpenTofu versions prior to 1.11.4, caused by malicious .zip archives processed by the tofu init command; no PoC, exploit, patch, or in‑the‑wild activity is detailed.

    0000030
    99 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-74797 OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or m… https://www.cve.org/CVERecord?id=CVE-2026-74797

    Post summary

    The post discloses CVE-2026-74797, a DoS flaw in OpenTofu <1.11.4 affecting the tofu init command when processing malicious .zip files, and notes that the issue is fixed in version 1.11.4.

    000001.5K
    58.0K followersView on X

Explore more