GHSA-7856-g3gv-9wq8

Suggest an improvement
Source
https://github.com/advisories/GHSA-7856-g3gv-9wq8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-7856-g3gv-9wq8/GHSA-7856-g3gv-9wq8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7856-g3gv-9wq8
Published
2026-07-07T20:04:22Z
Modified
2026-07-07T20:15:08.639549460Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
netfoil: Attacker controlled data written to logs
Details

Summary

Domain names were written to the log without first being validated to contain allowed characters.

Impact

Depends on how the logs were used.

Database specific
{
    "cwe_ids": [
        "CWE-117"
    ],
    "severity": "LOW",
    "github_reviewed_at": "2026-07-07T20:04:22Z",
    "github_reviewed": true,
    "nvd_published_at": null
}
References

Affected packages

Go / github.com/tinfoil-factory/netfoil

Package

Name
github.com/tinfoil-factory/netfoil
View open source insights on deps.dev
Purl
pkg:golang/github.com/tinfoil-factory/netfoil

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.3.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-7856-g3gv-9wq8/GHSA-7856-g3gv-9wq8.json"