CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-xvg2-cgv6-6h7v: netfoil: Incorrect block responses could lead to localhost traffic

high
Summary 0.0.0.0 was used instead of NXDOMAIN for block responses. On Linux, which is the target platform for netfoil, the 0.0.0.0 is sent to localhost rather than just dropped. Impact Unintended traffic could be sent to localhost. Impact depends on running services and firewall rules.

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
high
Published
2026-07-29
Last updated
2026-07-29
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-xvg2-cgv6-6h7v

More from GitHub Security Advisories