Junglewise Threat Intelligence

GO-2026-5558 - OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server in github.com/opentofu/opento

Severity: info · Published 2026-06-25

Technologies: github.com/opentofu/opentofu (Go). Vendors: Go.

Executive brief

OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server in github.com/opentofu/opentofu

Affected products

  • Go github.com/opentofu/opentofu

Related threats