{"id":"GHSA-xvg2-cgv6-6h7v","aliases":["GO-2026-6143"],"url":"https://o3.security/vulnerability/GHSA-xvg2-cgv6-6h7v","summary":"netfoil: Incorrect block responses could lead to localhost traffic","details":"### Summary\n`0.0.0.0` was used instead of NXDOMAIN for block responses. On Linux, which is the target platform for netfoil, the `0.0.0.0` is sent to localhost rather than just dropped.\n\n### Impact\nUnintended traffic could be sent to localhost. Impact depends on running services and firewall rules.","published":"2026-07-29T17:03:48Z","modified":"2026-08-18T15:11:06.019886818Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/tinfoil-factory/netfoil","fixedVersion":"0.4.0"}],"fix":{"url":"https://github.com/tinfoil-factory/netfoil/pull/33","label":"tinfoil-factory/netfoil#33"},"references":[{"type":"WEB","url":"https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-xvg2-cgv6-6h7v"},{"type":"WEB","url":"https://github.com/tinfoil-factory/netfoil/pull/33"},{"type":"WEB","url":"https://github.com/tinfoil-factory/netfoil/commit/891d3513c77999a9deef9f23506807d9653ee448"},{"type":"PACKAGE","url":"https://github.com/tinfoil-factory/netfoil"},{"type":"WEB","url":"https://github.com/tinfoil-factory/netfoil/releases/tag/v0.4.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T15:11:06.019886818Z"}}