GHSA-4ph6-mjv7-3fq6Low▾ Sunlitnetfoil vulnerable to improper handling of untrusted DoH response data
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
HTTPS RR data returned from the DoH server was not properly handled. Unverified APLN data (which could contain arbitrary byte sequences) was written directly to the log. It could also cause unnecessary memory usage. The single-byte response code was also written directly to the log.
github.com/tinfoil-factory/netfoil < 0.5.0Upgrade to a patched release:
github.com/tinfoil-factory/netfoil 0.5.0Connected by shared product, vendor, weakness, or advisory.
GO-2026-6277Nonenetfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil
GHSA-7856-g3gv-9wq8Lownetfoil: Attacker controlled data written to logs
GO-2026-6143Nonenetfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil
GHSA-xvg2-cgv6-6h7vHighnetfoil: Incorrect block responses could lead to localhost traffic
GO-2026-5935Nonenetfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil
GO-2026-5934Nonenetfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil