OpenTofu — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 29, 2025
Last Seen
December 29, 2025

OpenTofu is an open-source Terraform-compatible infrastructure-as-code tool used to manage cloud resources.

Overview

OpenTofu is an open-source Terraform-compatible infrastructure-as-code tool used to manage cloud resources. The Fedora 43 advisory identifies a critical memory-exhaustion denial-of-service vulnerability in OpenTofu, underscoring potential disruption to IaC workflows and deployments.

Related Threat Clusters

  • Fedora 43: Critical Vulnerabilities in OpenTofu and chezmoi

    Fedora 43 has issued critical advisories for two vulnerabilities affecting OpenTofu and chezmoi. OpenTofu version 1.11.2 addresses a memory exhaustion issue, while chezmoi version 2.68.1 resolves excessive CPU usage…

    2 articles · Updated December 29, 2025

Recent Intelligence Reports

  • Fedora 43: opentofu Critical DoS Memory Exhaustion Advisory 2025 — Linuxsecurity · December 29, 2025

CVSS v3.1 Breakdown