highVulnerability

GHSA-xvg2-cgv6-6h7v

### Summary `0.0.0.0` was used instead of NXDOMAIN for block responses. On Linux, which is the target platform for netfoil, the `0.0.0.0` is sent to localhost rather than just dropped. ### Impact Unintended traffic could be sent to localhost. Impact depends on running services and firewall rules.

Properties

ghsa_id
GHSA-xvg2-cgv6-6h7v
severity
high
summary
netfoil: Incorrect block responses could lead to localhost traffic
cve_id
GHSA-xvg2-cgv6-6h7v
is_ghsa_only
true
ghsa_published
2026-07-29T17:03:48Z
source_url
https://github.com/advisories/GHSA-xvg2-cgv6-6h7v
ghsa_updated
2026-07-29T17:03:48Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]go/github.com/tinfoil-factory/netfoil

AFFECTS (1)

[Software]go/github.com/tinfoil-factory/netfoil

HAS_WEAKNESS (1)

[Weakness]Protection Mechanism Failure

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph