GHSA-vjgj-42f6-7997

Suggest an improvement
Source
https://github.com/advisories/GHSA-vjgj-42f6-7997
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vjgj-42f6-7997/GHSA-vjgj-42f6-7997.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vjgj-42f6-7997
Aliases
Published
2026-04-29T22:23:41Z
Modified
2026-06-25T23:11:47Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
netfoil's optional seccomp sandboxing was not applied
Details

Summary

The optional flag --filter-system-calls was not applied even if specified.

Details

This is a defense in depth feature to apply additional seccomp filters after the binary has started. The example config also sandboxes the binary with systemd.

Impact

Reduced sandboxing of the netfoil binary.

Database specific
{
    "cwe_ids": [
        "CWE-791"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-29T22:23:41Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

Go / github.com/tinfoil-factory/netfoil

Package

Name
github.com/tinfoil-factory/netfoil
View open source insights on deps.dev
Purl
pkg:golang/github.com/tinfoil-factory/netfoil

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.2.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vjgj-42f6-7997/GHSA-vjgj-42f6-7997.json"