{"id":"GO-2026-6262","aliases":["GHSA-22w5-2fxg-vrwx"],"title":"OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or c…","summary":"OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu","severity":"none","vendor":"opentofu","product":"github.com/opentofu/opentofu","ecosystem":"go","affected":["github.com/opentofu/opentofu >= 1.12.0-beta1, < 1.12.2"],"patched":["github.com/opentofu/opentofu 1.12.2"],"published":"2026-08-25","updated":"2026-08-26","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GO-2026-6262","references":[{"url":"https://github.com/opentofu/opentofu/security/advisories/GHSA-22w5-2fxg-vrwx"},{"url":"https://github.com/opentofu/opentofu/issues/4242"},{"url":"https://github.com/opentofu/opentofu/issues/4243"},{"url":"https://github.com/opentofu/opentofu/issues/4244"},{"url":"https://github.com/opentofu/opentofu/releases/tag/v1.11.9"},{"url":"https://github.com/opentofu/opentofu/releases/tag/v1.12.2"}],"tags":["osv","go"],"ingestedAt":"2026-08-26T19:27:03.029Z","slug":"GO-2026-6262","body":"## Overview\n\nOpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu\n\n## Affected packages\n\n- `github.com/opentofu/opentofu >= 1.12.0-beta1, < 1.12.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/opentofu/opentofu 1.12.2`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}