<Vulnerability name="CVE-2026-74797">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Low</ThreatSeverity>
    <PublicDate>2026-08-16T13:14:19</PublicDate>
    <Bugzilla id="2517222" url="https://bugzilla.redhat.com/show_bug.cgi?id=2517222" xml:lang="en:us">
github.com/opentofu/opentofu: OpenTofu: Denial of Service via malicious zip archives
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>3.1</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-400</CWE>
    <Details xml:lang="en:us" source="Mitre">
OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in OpenTofu. A remote attacker could exploit this vulnerability by providing maliciously-crafted .zip archives during the `tofu init` command, which is used for provider or module package initialization. This could lead to excessive CPU usage, causing a Denial of Service (DoS) by degrading system performance and preventing the completion of the initialization process.
    </Details>
    <Statement xml:lang="en:us">
This Low impact denial of service vulnerability in OpenTofu affects the `tofu init` command when processing maliciously-crafted `.zip` archives. Exploitation requires an attacker to provide a malicious archive, necessitating user interaction or a compromised dependency supply chain, which limits the attack surface in Red Hat environments where `tofu init` is typically executed in controlled development or CI/CD pipelines.
    </Statement>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>hi/opentofu</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>opentofu1.10</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>opentofu1.11</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>opentofu1.12</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-74797
https://nvd.nist.gov/vuln/detail/CVE-2026-74797
https://github.com/opentofu/opentofu/security/advisories/GHSA-r92c-9c7f-3pj8
https://www.vulncheck.com/advisories/opentofu-before-denial-of-service-via-malicious-zip
    </References>
</Vulnerability>