UNKNOWN Go
OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responses in github.com/opentofu/opentofu
GO-2025-4101 · GHSA-w2jf-268q-mrvh
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responses in github.com/opentofu/opentofu
References
- ADVISORY https://github.com/opentofu/opentofu/security/advisories/GHSA-w2jf-268q-mrvh
- FIX https://github.com/opentofu/opentofu/pull/3467
- REPORT https://github.com/opentofu/opentofu/issues/3458
- REPORT https://github.com/opentofu/opentofu/issues/3462
- REPORT https://github.com/opentofu/opentofu/issues/3464
- REPORT https://github.com/opentofu/opentofu/issues/3465
- WEB https://github.com/opentofu/opentofu/releases/tag/v1.10.7
- WEB https://www.cve.org/CVERecord?id=CVE-2025-58183
- WEB https://www.cve.org/CVERecord?id=CVE-2025-58185
- WEB https://www.cve.org/CVERecord?id=CVE-2025-58187
- WEB https://www.cve.org/CVERecord?id=CVE-2025-58188
Ready to move
Start Securing
Free, no credit card | First findings in minutes