GO-2026-6262None▾ SunlitOpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu
github.com/opentofu/opentofu >= 1.12.0-beta1, < 1.12.2Upgrade to a patched release:
github.com/opentofu/opentofu 1.12.2Connected by shared product, vendor, weakness, or advisory.
GHSA-22w5-2fxg-vrwxLow· 2.6OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or c…
CVE-2024-58375High· 7.5OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations
CVE-2026-74796Medium· 6.1OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization
CVE-2026-74797Low· 3.1OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages
GHSA-wcmj-x466-56mmMedium· 6.1OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree
GHSA-q7j3-v8qv-22vqHigh· 7.5OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL