{"id":"GHSA-84g5-x8j3-7235","aliases":["GO-2026-5240"],"url":"https://o3.security/vulnerability/GHSA-84g5-x8j3-7235","summary":"Netfoil has incorrect allowlist enforcement","details":"### Summary\nRules could be bypassed by changing the first character: `example.com` could be be bypassed by e.g. `fxample.com`.\n\n### Details\nOff-by-one error in the suffixtrie implementation.\n\n### Impact\nThe domain filter could be bypassed. Please note that DNS filtering alone is not enough to block malicious traffic.","published":"2026-04-29T22:22:16Z","modified":"2026-06-25T19:56:39.293501071Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/tinfoil-factory/netfoil","fixedVersion":"0.2.1"}],"fix":{"url":"https://github.com/tinfoil-factory/netfoil/commit/0ca054acf97b011e4fdd40392475c7786b975ec3","label":"tinfoil-factory/netfoil@0ca054a"},"references":[{"type":"WEB","url":"https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-84g5-x8j3-7235"},{"type":"WEB","url":"https://github.com/tinfoil-factory/netfoil/commit/0ca054acf97b011e4fdd40392475c7786b975ec3"},{"type":"PACKAGE","url":"https://github.com/tinfoil-factory/netfoil"},{"type":"WEB","url":"https://github.com/tinfoil-factory/netfoil/releases/tag/v0.2.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-25T19:56:39.293501071Z"}}