PT-2026-60906 · Go · Github.Com/Tinfoil-Factory/Netfoil

Published

2026-07-07

·

Updated

2026-07-07

CVSS v4.0

5.9

Medium

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Summary

Potential bypass of domain name filter by crafting a DNS request with multiple questions, with the first question being legitimate.

Impact

Depends on a local attackers ability to craft multiple questions and the remote DoH server supporting them.

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-59QP-CFJ3-RP64

Affected Products

Github.Com/Tinfoil-Factory/Netfoil