CVE-2026-74796Medium· 6.1▾ SunlitOpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package content…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/opentofu/opentofu >= 1.11.0, < 1.11.7github.com/opentofu/opentofu < 1.10.10Patched in:
github.com/opentofu/opentofu 1.11.7github.com/opentofu/opentofu 1.10.10Connected by shared product, vendor, weakness, or advisory.
GHSA-22w5-2fxg-vrwxLow· 2.6OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or c…
CVE-2024-58375High· 7.5OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations
CVE-2026-74797Low· 3.1OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages
GHSA-wcmj-x466-56mmMedium· 6.1OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree
GO-2026-6262NoneOpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or c…
GHSA-q7j3-v8qv-22vqHigh· 7.5OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL