What is CVE-2026-74797?
CVE-2026-74797 is a denial of service vulnerability in OpenTofu versions before 1.11.4 affecting the `tofu init` command. Maliciously-crafted .zip archives for provider or module packages can cause excessive CPU usage during dependency installation. Upgrading to the latest version is recommended.
Azərbaycanca: CVE-2026-74797 OpenTofu-nun 1.11.4-dən əvvəlki versiyalarında `tofu init` əmrində xidmət rəddi zəifliyidir. Təhlükəli .zip arxivləri vasitəsilə provayder və ya modul paketləri emal edilərkən həddindən artıq CPU istifadəsi baş verə bilər. OpenTofu-nu ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which OpenTofu command is affected by CVE-2026-74797?
This vulnerability affects OpenTofu's `tofu init` command.
What is recommended to mitigate CVE-2026-74797?
It is recommended to upgrade OpenTofu to the latest version (1.11.4 or newer).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.