GHSA-7856-g3gv-9wq8Low▾ Sunlitnetfoil: Attacker controlled data written to logs
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Domain names were written to the log without first being validated to contain allowed characters.
Depends on how the logs were used.
github.com/tinfoil-factory/netfoil < 0.3.0Upgrade to a patched release:
github.com/tinfoil-factory/netfoil 0.3.0Connected by shared product, vendor, weakness, or advisory.
GHSA-4ph6-mjv7-3fq6Lownetfoil vulnerable to improper handling of untrusted DoH response data
GO-2026-5935Nonenetfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil
GO-2026-6277Nonenetfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil
GO-2026-6143Nonenetfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil
GHSA-xvg2-cgv6-6h7vHighnetfoil: Incorrect block responses could lead to localhost traffic
GO-2026-5934Nonenetfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil