Technology · Go
github.com/opentofu/opentofu (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 15 vulnerabilities in github.com/opentofu/opentofu (Go): 0 in the last 7 days and 3 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, GO-2026-6262 - OpenTofu has high CPU usage when using K8S remote state backend…, was published on 25 August 2026.
- Last 7 days
- 0
- Last 90 days
- 3
- Critical, all time
- 0
- Exploited in the wild
- 0
About github.com/opentofu/opentofu (Go)
An open-source infrastructure as code tool that provides a fork of Terraform for managing cloud and on-premises resources.
Latest github.com/opentofu/opentofu (Go) vulnerabilities
- GO-2026-6262 - OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from…info
- CVE-2026-74797: OpenTofu denial of service in tofu init with malicious .zip archiveslowCVSS 3.1EPSS 0.3%
- CVE-2026-74796: OpenTofu symlink following in provider cache directorymediumCVSS 6.1EPSS 0.3%
- GO-2026-5558 - OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server in…info
- GO-2026-5571 - OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL in…info
- GO-2026-5441 - OpenTofu has unbounded memory usage, high CPU usage, or deadlock in "tofu init" with maliciously-crafted dependency…info
- OpenTofu infinite loop in tofu init via malicious HTTP2 serverlowCVSS 3.1
- OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled serverlowCVSS 3.1
- OpenTofu denial of service in tofu init via malicious dependencieslowCVSS 3.1
- OpenTofu has unbounded memory usage, high CPU usage, or deadlock in "tofu init" with maliciously-crafted dependency responseslowCVSS 3.1
- GO-2025-4224 - OpenTofu incorrectly validates excluded subdomain constraint in conjunction with TLS certificates containing wildcard SANs…info
- OpenTofu incorrectly validates excluded subdomain constraint in conjunction with TLS certificates containing wildcard SANslowCVSS 3.1
- GO-2025-4101 - OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responses in…info
- OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responseslowCVSS 3.1
- CVE-2024-58375: GO-2024-3182 - OpenTofu potential leaking of secret variable values when using static evaluation in v1.8 in…lowCVSS 3.1EPSS 0.4%
Most severe github.com/opentofu/opentofu (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-74796: OpenTofu symlink following in provider cache directorymediumCVSS 6.1EPSS 0.3%
- CVE-2024-58375: GO-2024-3182 - OpenTofu potential leaking of secret variable values when using static evaluation in v1.8 in…lowCVSS 3.1EPSS 0.4%
- CVE-2026-74797: OpenTofu denial of service in tofu init with malicious .zip archiveslowCVSS 3.1EPSS 0.3%
- OpenTofu infinite loop in tofu init via malicious HTTP2 serverlowCVSS 3.1
- OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled serverlowCVSS 3.1
- OpenTofu has unbounded memory usage, high CPU usage, or deadlock in "tofu init" with maliciously-crafted dependency responseslowCVSS 3.1
- OpenTofu denial of service in tofu init via malicious dependencieslowCVSS 3.1
- OpenTofu incorrectly validates excluded subdomain constraint in conjunction with TLS certificates containing wildcard SANslowCVSS 3.1
- OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responseslowCVSS 3.1
- GO-2026-6262 - OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from…info
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 2 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/github-com-opentofu-opentofu.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "github.com/opentofu/opentofu (Go) vulnerabilities", https://junglewise.ai/threats/technologies/github-com-opentofu-opentofu, 28 September 2026.