PT-2026-68310 · Unknown · Boringproxy

·

CVE-2026-70615

·

Published

2026-08-05

·

Updated

2026-08-06

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions boringproxy versions prior to 0.10.1
Description Authenticated low-privileged users with tunnel-creation permissions can perform a newline injection. By providing a percent-encoded newline character in the domain parameter of the tunnel creation endpoint, an attacker can inject arbitrary lines into the server account's SSH authorized keys file. This allows the insertion of an unrestricted public key to obtain persistent shell access, enabling the attacker to read cleartext credentials from the database file, including all user tokens, tunnel private keys, and TLS certificates.
Recommendations Update boringproxy to a version newer than 0.10.0. Avoid using the domain parameter in the tunnel creation endpoint until the software is updated.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70615

Affected Products

Boringproxy