{"id":"CGA-9f9g-mhpv-42rr","modified":"2026-01-28T03:26:48.592477Z","published":"2025-11-04T01:03:44.295313Z","withdrawn":"2026-01-28T03:26:48.592477Z","related":["CGA-9f9g-mhpv-42rr","CVE-2025-61725","GHSA-qh38-484v-w52x"],"affected":[{"package":{"name":"opentofu-1.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/opentofu-1.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.4-r2"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-9f9g-mhpv-42rr.json"}},{"package":{"name":"opentofu-1.9-compat","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/opentofu-1.9-compat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.4-r2"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-9f9g-mhpv-42rr.json"}},{"package":{"name":"opentofu-1.9-local-provider-config","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/opentofu-1.9-local-provider-config"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.4-r2"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-9f9g-mhpv-42rr.json"}}],"schema_version":"1.7.3"}