github.com/opentofu/opentofu vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-WCMJ-X466-56MMMediumgithub.com/opentofu/opentofu: OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working treeGHSA-Q7J3-V8QV-22VQHighgithub.com/opentofu/opentofu: OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URLGHSA-PXH5-6RRC-8RJVLowgithub.com/opentofu/opentofu: OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled serverGHSA-HW5X-4R37-72W7Lowgithub.com/opentofu/opentofu: OpenTofu has unbounded memory usage, high CPU usage, or deadlock in "tofu init" with maliciously-crafted dependency responsesGHSA-R92C-9C7F-3PJ8Lowgithub.com/opentofu/opentofu: OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip formatGHSA-MJCP-GPGX-GGCGMediumgithub.com/opentofu/opentofu: OpenTofu incorrectly validates excluded subdomain constraint in conjunction with TLS certificates containing wildcard SANsGHSA-W2JF-268Q-MRVHLowgithub.com/opentofu/opentofu: OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responsesGHSA-WPR2-J6GR-PJW9Lowgithub.com/opentofu/opentofu: OpenTofu potential leaking of secret variable values when using static evaluation in v1.8

Stop the waste.
Protect your environment with Kodem.