VulnSea

opentofu has 7 CVEs on record. Disclosure cadence is accelerating: 5 in the last 90 days against 2 in the 90 before. The busiest recent month was August 2026 with 5. The median CVSS is 6.1 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
5 prev 2

Products

  • github.com/opentofu/opentofu 7
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

opentofu vulnerabilities

CVEs affecting opentofu, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

GO-2026-6262None
4w ago

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or c…

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu

Sunlitopentofu · github.com/opentofu/opentofuvia OSV
GHSA-22w5-2fxg-vrwxLow· 2.6
1mo ago

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or c…

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers

Sunlitopentofu · github.com/opentofu/opentofuvia OSV
CVE-2024-58375High· 7.5⚖ disputed
1mo ago

OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations

OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive m…

Twilightopentofu · github.com/opentofu/opentofuEPSS 0.26%via NVD
CVE-2026-74796Medium· 6.1
1mo ago

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package content…

Sunlitopentofu · github.com/opentofu/opentofuEPSS 0.23%via NVD
CVE-2026-74797Low· 3.1
1mo ago

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling …

Sunlitopentofu · github.com/opentofu/opentofuEPSS 0.17%via NVD
GHSA-wcmj-x466-56mmMedium· 6.1
3mo ago

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree

Sunlitopentofu · github.com/opentofu/opentofuvia GHSA
GHSA-q7j3-v8qv-22vqHigh· 7.5
3mo ago

OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL

OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL

Twilightopentofu · github.com/opentofu/opentofuvia GHSA
opentofu vulnerabilities (CVEs) · VulnSea