GHSA-xvg2-cgv6-6h7v

Suggest an improvement
Source
https://github.com/advisories/GHSA-xvg2-cgv6-6h7v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-xvg2-cgv6-6h7v/GHSA-xvg2-cgv6-6h7v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xvg2-cgv6-6h7v
Aliases
Published
2026-07-29T17:03:48Z
Modified
2026-08-18T15:11:06Z
Severity
  • 7.4 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
netfoil: Incorrect block responses could lead to localhost traffic
Details

Summary

0.0.0.0 was used instead of NXDOMAIN for block responses. On Linux, which is the target platform for netfoil, the 0.0.0.0 is sent to localhost rather than just dropped.

Impact

Unintended traffic could be sent to localhost. Impact depends on running services and firewall rules.

Database specific
{
    "cwe_ids":  [
        "CWE-693"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-29T17:03:48Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Go / github.com/tinfoil-factory/netfoil

Package

Name
github.com/tinfoil-factory/netfoil
View open source insights on deps.dev
Purl
pkg:golang/github.com/tinfoil-factory/netfoil

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-xvg2-cgv6-6h7v/GHSA-xvg2-cgv6-6h7v.json"