Summary
netfoil: Incorrect block responses could lead to localhost traffic
Advisory details
Summary
0.0.0.0 was used instead of NXDOMAIN for block responses. On Linux, which is the target platform for netfoil, the 0.0.0.0 is sent to localhost rather than just dropped.
Impact
Unintended traffic could be sent to localhost. Impact depends on running services and firewall rules.
References
- https://github.com/advisories/GHSA-xvg2-cgv6-6h7v
- https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-xvg2-cgv6-6h7v
- https://github.com/tinfoil-factory/netfoil/pull/33
- https://github.com/tinfoil-factory/netfoil/commit/891d3513c77999a9deef9f23506807d9653ee448
- https://github.com/tinfoil-factory/netfoil/releases/tag/v0.4.0
Related vulnerabilities
All Supply chain →- HIGHGHSA-8cfw-pcwh-v63w
Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)
- MEDIUMGHSA-9w56-46f6-3qhx
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
- CRITICALCVE-2026-47686
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
- MEDIUMCVE-2026-62902
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
- HIGHGHSA-f5wm-88jv-g5hx
Craft CMS: Authenticated RCE through Twig sandbox escape
- HIGHCVE-2026-70608
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path