Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2135117
AlmaLinux
5767
Alpaquita
14296
Alpine
4586
Android
3666
Azure Linux
16014
BellSoft Hardened Containers
738
Bitnami
9134
Chainguard
991927
CleanStart
3765
CRAN
14
crates.io
2695
Debian
65570
Echo
8852
GHC
3
GIT
103395
GitHub Actions
55
Go
9065
Hackage
32
Hex
329
Julia
1713
Linux
28061
Mageia
6160
Maven
6958
MinimOS
139376
npm
228261
NuGet
1852
opam
29
openEuler
8374
openSUSE
14215
OSS-Fuzz
3993
Packagist
6990
Pub
11
PyPI
24995
Red Hat
22826
Rocky Linux
4137
Root
19284
RubyGems
4709
SUSE
22736
SwiftURL
59
TuxCare
8923
Ubuntu
62552
VSCode
21
Wolfi
278979
ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-74797
github.com/opentofu/opentofu
OpenTofu before 1.11.4 Denial of Service via malicious zip
16 Aug
Fix available
Severity - 2.3 (Low)
CLEANSTART-2026-XN15507
CleanStart/opentofu-fips
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions
30 Apr
Fix available
Severity - 9.8 (Critical)
CLEANSTART-2026-OM95908
CleanStart/opentofu-fips
Security fixes for CVE-2025-47913, CVE-2025-47914, CVE-2025-58181, CVE-2025-61727, CVE-2025-61729, CVE-2026-1229, CVE-2026-24051, CVE-2026-25679, CVE-2026-27139, CVE-2026-27142, CVE-2026-33186, ghsa-2464-8j7c-4cjm, ghsa-2x5j-vhc8-9cwm, ghsa-6v2p-p543-phr9, ghsa-c6gw-w398-hv78, ghsa-fv92-fjc5-jj9h, ghsa-hcg3-q754-cr77, ghsa-jc7w-c686-c4v9, ghsa-mh63-6h87-95cp, ghsa-p77j-4mvh-x3m3, ghsa-qxp5-gwg8-xv66, ghsa-r92c-9c7f-3pj8, ghsa-vvgc-356p-c3xw, ghsa-wjrx-6529-hcj3 applied in versions: 1.10.7-r0, 1.10.7-r1, 1.11.4-r0, 1.11.5-r0, 1.11.5-r1, 1.11.5-r2, 1.9.4-r0
01 Apr
Fix available
CLEANSTART-2026-GG58376
CleanStart/opentofu-fips
Within HostnameError
17 Feb
Fix available
Severity - 9.8 (Critical)
GO-2026-4352
Go/github.com/opentofu/opentofu
OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip format in github.com/opentofu/opentofu
02 Feb
Fix available
CGA-38r8-9cf5-xp9p
Chainguard/opentofu-1.9
Wolfi/opentofu-1.9
See record for full details
22 Jan
No fix available
Severity - 3.1 (Low)
CGA-2hjj-wjcr-hfrw
Chainguard/opentofu-1.9
Wolfi/opentofu-1.9
See record for full details
22 Jan
No fix available
Severity - 3.1 (Low)
CGA-6vrc-rcw9-3jvg
Chainguard/opentofu-fips-1.8
See record for full details
22 Jan
No fix available
Severity - 3.1 (Low)
CGA-2232-3vvw-jxc4
Chainguard/opentofu-fips-1.8
See record for full details
22 Jan
No fix available
Severity - 3.1 (Low)
CGA-wqj7-ccvv-p29v
Chainguard/opentofu-1.8
See record for full details
22 Jan
No fix available
Severity - 3.1 (Low)
CGA-7qpw-vg3v-mx93
Chainguard/opentofu-1.8
See record for full details
22 Jan
No fix available
Severity - 3.1 (Low)
CGA-wcfq-j92v-pwg5
Chainguard/opentofu-fips-1.9
See record for full details
22 Jan
No fix available
Severity - 3.1 (Low)
CGA-29fj-w92p-qr7m
Chainguard/opentofu-fips-1.9
See record for full details
22 Jan
No fix available
Severity - 3.1 (Low)
CGA-xx7r-qrjv-h4gh
Chainguard/opentofu-1.11
Wolfi/opentofu-1.11
See record for full details
22 Jan
Fix available
Severity - 3.1 (Low)
CGA-wv3r-g6mj-8m89
Chainguard/opentofu-1.11
Wolfi/opentofu-1.11
See record for full details
22 Jan
Fix available
Severity - 3.1 (Low)
CGA-qr8p-mgxq-48v9
Chainguard/opentofu-fips-1.10
See record for full details
22 Jan
No fix available
Severity - 3.1 (Low)
Load more...
Vulnerability Database - OSV