mediumVulnerability
GHSA-84g5-x8j3-7235
### Summary Rules could be bypassed by changing the first character: `example.com` could be be bypassed by e.g. `fxample.com`. ### Details Off-by-one error in the suffixtrie implementation. ### Impact The domain filter could be bypassed. Please note that DNS filtering alone is not enough to block malicious traffic.
Properties
- ghsa_id
- GHSA-84g5-x8j3-7235
- severity
- medium
- summary
- Netfoil has incorrect allowlist enforcement
- cve_id
- GHSA-84g5-x8j3-7235
- is_ghsa_only
- true
- ghsa_published
- 2026-04-29T22:22:16Z
- source_url
- https://github.com/advisories/GHSA-84g5-x8j3-7235
- ghsa_updated
- 2026-04-29T22:22:17Z
Related Entities (5)
VULNERABLE_TO (1)
←[Software]go/github.com/tinfoil-factory/netfoil
AFFECTS (1)
→[Software]go/github.com/tinfoil-factory/netfoil
HAS_WEAKNESS (2)
→[Weakness]Off-by-one Error
→[Weakness]Permissive List of Allowed Inputs
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph