{"id":"GO-2025-4101","summary":"OpenTofu affected denials of service in \"tofu init\" with maliciously-crafted module package responses in github.com/opentofu/opentofu","details":"OpenTofu affected denials of service in \"tofu init\" with maliciously-crafted module package responses in github.com/opentofu/opentofu","aliases":["GHSA-w2jf-268q-mrvh"],"modified":"2026-02-04T03:37:15.495454Z","published":"2025-11-17T19:11:23Z","related":["CGA-5x62-3qxg-m47w"],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2025-4101"},"references":[{"type":"ADVISORY","url":"https://github.com/opentofu/opentofu/security/advisories/GHSA-w2jf-268q-mrvh"},{"type":"FIX","url":"https://github.com/opentofu/opentofu/pull/3467"},{"type":"REPORT","url":"https://github.com/opentofu/opentofu/issues/3458"},{"type":"REPORT","url":"https://github.com/opentofu/opentofu/issues/3462"},{"type":"REPORT","url":"https://github.com/opentofu/opentofu/issues/3464"},{"type":"REPORT","url":"https://github.com/opentofu/opentofu/issues/3465"},{"type":"WEB","url":"https://github.com/opentofu/opentofu/releases/tag/v1.10.7"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2025-58183"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2025-58185"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2025-58187"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2025-58188"}],"affected":[{"package":{"name":"github.com/opentofu/opentofu","ecosystem":"Go","purl":"pkg:golang/github.com/opentofu/opentofu"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.10.7"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-4101.json"}}],"schema_version":"1.7.3"}