Netfoil has incorrect allowlist enforcement
Moderate severity
GitHub Reviewed
Published
Apr 22, 2026
in
tinfoil-factory/netfoil
•
Updated Apr 29, 2026
Description
Published to the GitHub Advisory Database
Apr 29, 2026
Reviewed
Apr 29, 2026
Last updated
Apr 29, 2026
Summary
Rules could be bypassed by changing the first character:
example.comcould be be bypassed by e.g.fxample.com.Details
Off-by-one error in the suffixtrie implementation.
Impact
The domain filter could be bypassed. Please note that DNS filtering alone is not enough to block malicious traffic.
References