Executive brief
OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responses
Affected products
- Go github.com/opentofu/opentofu
Junglewise Threat Intelligence
Severity: low · CVSS 3.1 · Published 2025-11-06
Technologies: github.com/opentofu/opentofu (Go). Vendors: Go.
OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responses