Package
opentofu-1.9
Component
github.com/opentofu/opentofu
Latest update
3.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Upstream does not plan to fix this CVE as it requires a go-bump to 1.24.9 they do not wish to apply for backward compatibility reasons[1]. Chainguard's opentofu packages are built with go 1.25.3. [1] https://github.com/advisories/GHSA-w2jf-268q-mrvh
Status