The optional flag --filter-system-calls was not applied even if specified.
This is a defense in depth feature to apply additional seccomp filters after the binary has started. The example config also sandboxes the binary with systemd.
Reduced sandboxing of the netfoil binary.
{
"cwe_ids": [
"CWE-791"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-29T22:23:41Z",
"nvd_published_at": null,
"severity": "MODERATE"
}