CVE-2026-74797
CVE-2026-74797: 1 tracked advisory record across Red Hat. Compare vendor sources.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityLow3.1
Low [CVE-2026-74797] Denial of Service via malicious zip archives
CVE-2026-74797Source published Source updated
OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted.zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling.zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process. A flaw was found in OpenTofu. Exploitation requires an attacker to provide a malicious archive, necessitating user interaction or a compromised dependency supply chain, which limits the attack surface in Red Hat environments where `tofu init` is typically executed in controlled development or CI/CD pipelines. Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-400. Red Hat…
- Affected products in this advisory
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- < 1.11.4
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.