GHSA-xvg2-cgv6-6h7vHigh▾ Twilightnetfoil: Incorrect block responses could lead to localhost traffic
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
0.0.0.0 was used instead of NXDOMAIN for block responses. On Linux, which is the target platform for netfoil, the 0.0.0.0 is sent to localhost rather than just dropped.
Unintended traffic could be sent to localhost. Impact depends on running services and firewall rules.
github.com/tinfoil-factory/netfoil < 0.4.0Upgrade to a patched release:
github.com/tinfoil-factory/netfoil 0.4.0Connected by shared product, vendor, weakness, or advisory.
GO-2026-6143Nonenetfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil
GHSA-59qp-cfj3-rp64Mediumnetfoil has a domain name filter bypass via multiple questions
GO-2026-6277Nonenetfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil
GHSA-4ph6-mjv7-3fq6Lownetfoil vulnerable to improper handling of untrusted DoH response data
GO-2026-5935Nonenetfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil
GO-2026-5934Nonenetfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil