Status
Impact
Upstream does not plan to fix this CVE as it requires a go-bump to 1.24.9 they do not wish to apply for backward compatibility reasons[1]. Chainguard's opentofu packages are built with go 1.25.3. [1] https://github.com/advisories/GHSA-w2jf-268q-mrvh
Status