CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-XVG2-CGV6-6H7V

GHSA-XVG2-CGV6-6H7V: Local Traffic Interception and Information Disclosure via Improper DNS Block Responses in netfoil

Amit Schendel
Amit Schendel
Senior Security Researcher

Jul 29, 2026·6 min read·21 visits

Executive Summary (TL;DR)

netfoil DNS proxy returned 0.0.0.0 (NOERROR) for blocked domains, causing Linux systems to route traffic to localhost where local services could intercept credentials.

A protection mechanism failure in the netfoil DNS proxy prior to version 0.4.0 causes blocked domains to resolve to null IP addresses (0.0.0.0 or ::) with a NOERROR status instead of NXDOMAIN. On Linux systems, connections to these addresses are routed to the loopback interface (localhost), allowing local processes to intercept sensitive HTTP traffic, including authorization headers and session cookies, intended for the blocked domains.

Vulnerability Overview

The Go-based minimal DNS proxy netfoil provides domain-level filtering to block trackers, ads, and malicious sites. Prior to version 0.4.0, the proxy failed to implement secure domain blocking mechanics, leading to a severe protection mechanism failure classified under CWE-693.\n\nInstead of returning a standard Non-Existent Domain (NXDOMAIN) status, netfoil returned a successful NOERROR DNS response containing dummy A, AAAA, or HTTPS records. These dummy records resolved to null IP addresses (0.0.0.0 or ::), signaling to the querying application that the domain was active and reachable.\n\nThis behavior exposes clients, especially those on Linux platforms, to local traffic interception. When client applications attempt to connect to the resolved null IPs, the OS kernel routes the requests back to the local loopback interface (localhost). Consequently, any unprivileged local process listening on the target ports can intercept sensitive transaction details, including session cookies and authorization tokens, originally intended for the blocked external domain.

Root Cause Analysis

The root cause of the vulnerability lies in the implementation of the generateBlockResponse function within dns/filter.go. Instead of dropping the query or returning an error status, the function explicitly constructed a DNS answer containing an active resource record pointing to ipv4Null (0.0.0.0) or ipv6Null (::) and marked the response header flags with ResponseCodeNoError.\n\nWhen a client operating system receives this response, the local resolver interprets it as a fully valid, successful domain resolution. On Linux platforms, the kernel's routing table treats connections to 0.0.0.0 or :: as aliases for the loopback address (127.0.0.1 or ::1). Therefore, instead of terminating the connection attempt or generating a connection-refused error, the client browser or application initiates a three-way TCP handshake with localhost.\n\nThis design flaw introduces a severe vulnerability when local services run on matching ports (e.g., 80 or 443). Because the client browser believes it is communicating with the legitimate external host (for example, analytics.company.com), it transmits standard HTTP headers, cookies, and tokens over this loopback connection. An unprivileged local daemon or web server can accept these connections and capture high-value credentials.

Code Analysis

The vulnerable version of dns/filter.go constructed the blocked response by setting the RCODE to ResponseCodeNoError and appending dummy IPv4 and IPv6 null values in the answers slice:\n\ngo\n// Vulnerable Implementation\nfunc generateBlockResponse(question Question) *Response {\n\tdomain := question.Name\n\trecordType := question.Type\n\n\tvar response *Response\n\tflags := Flags{\n\t\tRCODE: ResponseCodeNoError, // ERROR: Signals successful resolution\n\t}\n\n\tif recordType == RecordTypeA || recordType == RecordTypeAAAA {\n\t response = &Response{\n\t Flags: flags,\n\t Answers: []Answer{\n\t {\n\t Name: domain,\n\t Type: recordType,\n\t Class: ClassTypeIN,\n\t TTL: defaultTTL,\n\t IPv4: ipv4Null, // 0.0.0.0\n\t IPv6: ipv6Null, // ::\n\t },\n\t },\n\t }\n\t} // ... HTTPS record logic also used ipv4Null / ipv6Null\n\n\nIn version 0.4.0, the package was refactored to remove the creation of synthetic resource records entirely. The updated logic changes the response code to ResponseCodeNXDomain and sets the answers to nil:\n\ngo\n// Patched Implementation in Commit 891d3513c77999a9deef9f23506807d9653ee448\nfunc generateBlockResponse() *Response {\n\tvar response *Response\n\tflags := Flags{\n\t\tRCODE: ResponseCodeNXDomain, // FIX: Informs client the domain does not exist\n\t}\n\n\tresponse = &Response{\n\t Flags: flags,\n\t Answers: nil, // FIX: Empty answer block forces connection failure\n\t}\n\n\treturn response\n}\n\n\nThis patch completely eliminates the routing of blocked requests to localhost. The client's operating system resolver instantly aborts connection attempts when encountering an NXDOMAIN response code, ensuring that no local ports are contacted.

Exploitation & Attack Scenarios

Exploitation of GHSA-XVG2-CGV6-6H7V is straightforward and requires no active privileges or authentication. Below is a representation of the routing flow during an exploitation attempt:\n\nmermaid\ngraph LR\n Client["Client App / Browser"] -->|"1. Query: tracker.com"| Proxy["Vulnerable netfoil"]\n Proxy -->|"2. Response: 0.0.0.0 (NoError)"| Client\n Client -->|"3. TCP Handshake to 0.0.0.0:80"| Kernel["Linux Kernel Routing"]\n Kernel -->|"4. Redirects connection"| Localhost["Local Listener (Port 80/443)"]\n\n\nAn attacker operating on the same machine as the victim (e.g., in a multi-user environment or via a malicious low-privilege script) can bind to the target port on localhost (such as 8080 or 80). When the victim's application triggers a background request to a blocked tracker, netfoil resolves the domain to 0.0.0.0, routing the traffic directly into the attacker's listener.\n\nOnce connected, the victim's client transmits a fully populated HTTP request. Since the client thinks it is communicating with the legitimate domain, the request includes active Session IDs, Bearer tokens, and Authorization headers. The attacker can log these headers to hijack sessions or gain unauthorized API access.

Security Impact Assessment

The security impact of this vulnerability is significant, particularly in development, corporate, or shared Linux environments where netfoil is deployed. By resolving blocked domains to local loopback addresses, the proxy undermines the security isolation between external web services and local applications.\n\nFurthermore, this flaw enables Same-Origin Policy (SOP) bypasses. Because the browser continues to map the domain name to the request, cookies scoped to the blocked domain are transmitted to localhost, allowing local malicious pages or applications to execute Cross-Site Request Forgery (CSRF) or Server-Side Request Forgery (SSRF) actions against services running on the loopback interface.\n\nThe CVSS v4.0 score is assessed at 7.4 (High), reflecting high confidentiality and integrity impacts on the affected host, with a low attack complexity. Although exploitation relies on specific local state conditions, the automated nature of modern web browsers makes exploitation highly reliable once those conditions are met.

Remediation & Patch Completeness

To remediate this issue, administrators and developers must upgrade netfoil to version 0.4.0 or later. This version incorporates the correct NXDOMAIN behavior, which stops DNS resolution on the client side without executing local loops.\n\nIf upgrading is not immediately possible, temporary mitigation can be achieved by overriding local routing behaviors or applying local firewall policies. Specifically, rules can be created using iptables or nftables to drop outgoing packets destined to 0.0.0.0 or :: that are not originating from local control interfaces.\n\nAnalysis of the patch confirms that the fix is complete. By shifting from dummy address spoofing to standard NXDOMAIN responses, the root cause—relying on invalid/routable address translation—is fully eradicated, ensuring that variant attacks utilizing alternative local loopback ranges are blocked.

Fix Analysis (1)

Technical Appendix

CVSS Score
7.4/ 10
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Systems

Linux installations utilizing netfoil DNS proxyContainers and platforms running applications that compromise netfoil filtering

Affected Versions Detail

Product
Affected Versions
Fixed Version
netfoil
tinfoil-factory
< 0.4.0v0.4.0
AttributeDetail
CWE IDCWE-693
Attack VectorNetwork
CVSS v4.07.4
ImpactHigh (Confidentiality & Integrity)
Exploit StatusProof of Concept (PoC) available
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1562.001Impair Defenses: Disable or Modify System Firewall
Defense Evasion
T1557Adversary-in-the-Middle (AiTM)
Collection
T1185Browser Session Hijacking
Collection
CWE-693
Protection Mechanism Failure

The product fails to correctly configure or execute a security mechanism, thereby failing to defend against unauthorized connection interception or routing behaviors.

Vulnerability Timeline

Pull Request #33 created and merged
2026-06-08
Fix commit 891d3513c77999a9deef9f23506807d9653ee448 finalized
2026-06-08
GitHub Security Advisory GHSA-XVG2-CGV6-6H7V published
2026-07-29

References & Sources

  • [1]GHSA-XVG2-CGV6-6H7V: Local traffic interception in netfoil
  • [2]Official Advisory Page on Repository
  • [3]Fix Pull Request #33
  • [4]Fix Commit Diff
  • [5]v0.4.0 Release Page

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•39 minutes ago•CVE-2026-107725
8.7

CVE-2026-107725: Remote Code Execution via Authorization Bypass in Hazelcast Predicates API

CVE-2026-107725 is a critical security bypass in Hazelcast where missing authorization checks in the MapPermission class permit unprivileged clients to issue queries containing aggregators or projections. This architectural oversight allows attackers to run arbitrary code on the cluster servers under the privileges of the active Hazelcast process.

Amit Schendel
Amit Schendel
1 views•7 min read
•about 2 hours ago•CVE-2026-107396
5.4

CVE-2026-107396: Stored Cross-Site Scripting (XSS) in Indico

A stored Cross-Site Scripting (XSS) vulnerability was identified in Indico, an open-source event management system developed at CERN, prior to version 3.3.13. The vulnerability stems from weak URL validation in custom link fields and lack of HTML sanitization during Marshmallow serialization of event notes. This allows authenticated attackers with event modification privileges to inject malicious payloads that execute in the browser of users viewing the event pages or collaborating on notes.

Alon Barad
Alon Barad
2 views•6 min read
•about 3 hours ago•CVE-2026-107397
4.4

CVE-2026-107397: Stored Cross-Site Scripting via Collaborative Editor Conflict Resolution and Custom Link Fields in Indico

A technical analysis of CVE-2026-107397, a stored Cross-Site Scripting (XSS) vulnerability in Indico's collaborative notes editor and custom link generation fields. Prior to version 3.3.13, Marshmallow serialization schemas omitted HTML sanitization during conflict resolution, and form validators failed to enforce strict URI schemes, enabling authenticated low-privilege attackers to execute arbitrary JavaScript.

Alon Barad
Alon Barad
0 views•7 min read
•about 4 hours ago•CVE-2026-107395
4.3

CVE-2026-107395: Missing Authorization in Indico Legacy Session Export API

An authorization bypass vulnerability exists in the legacy session export API of Indico, an open-source event management system developed at CERN. Due to a missing object-level access check, authenticated users can bypass configuration-level restrictions to extract private session metadata (including session titles, descriptions, and list of conveners) from events that they are otherwise authorized to view.

Alon Barad
Alon Barad
8 views•5 min read
•about 5 hours ago•CVE-2026-107394
6.8

CVE-2026-107394: Server-Side Request Forgery Bypass via Parser Differential in Indico

An incomplete Server-Side Request Forgery (SSRF) validation check in Indico prior to version 3.3.13 allows authenticated event organizers to bypass outbound network restrictions. By utilizing backslash characters within crafted URLs, attackers can exploit a parser differential between the application's validator and the downstream HTTP client library to access internal network resources.

Alon Barad
Alon Barad
7 views•6 min read
•about 6 hours ago•CVE-2026-107717
6.5

CVE-2026-107717: Chat Role Injection and Prompt Boundary Bypass in Banks Library

CVE-2026-107717 represents a critical prompt boundary bypass and chat role injection vulnerability in the Banks Python package (versions prior to 2.5.0). The library parses generated template outputs line-by-line, attempting to validate each segment as a JSON-serialized ChatMessage object without validating the source boundaries of the text. If an application integrates user input directly into a prompt template, a remote, unauthenticated attacker can supply multi-line inputs with structured JSON payloads. This input is then parsed as high-privilege system instructions or tool execution responses, completely hijacking downstream Large Language Model behavior.

Alon Barad
Alon Barad
8 views•6 min read