lowVulnerability

GHSA-7856-g3gv-9wq8

### Summary Domain names were written to the log without first being validated to contain allowed characters. ### Impact Depends on how the logs were used.

Properties

ghsa_id
GHSA-7856-g3gv-9wq8
summary
netfoil: Attacker controlled data written to logs
severity
low
cve_id
GHSA-7856-g3gv-9wq8
is_ghsa_only
true
ghsa_published
2026-07-07T20:04:22Z
source_url
https://github.com/advisories/GHSA-7856-g3gv-9wq8
ghsa_updated
2026-07-07T20:04:23Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/tinfoil-factory/netfoil

AFFECTS (1)

[Software]go/github.com/tinfoil-factory/netfoil

HAS_WEAKNESS (1)

[Weakness]Improper Output Neutralization for Logs

Explore deeper with Ninja Signal's threat intelligence graph