CVE-2026-70615

Source
https://cve.org/CVERecord?id=CVE-2026-70615
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70615.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-70615
Published
2026-08-05T19:34:13.322Z
Modified
2026-08-08T03:30:50.286459975Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H CVSS Calculator
Summary
boringproxy 0.10.0 SSH authorized_keys Injection via Tunnel Creation
Details

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorizedkeys file by supplying a percent-encoded newline character in the domain parameter of the tunnel creation endpoint. Attackers can insert an unrestricted public key entry into authorizedkeys to gain persistent shell access, and subsequently read cleartext credentials from the database file including all user tokens, tunnel private keys, and TLS certificates.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70615.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-93"
    ]
}
References

Affected packages

Git / github.com/boringproxy/boringproxy

Affected ranges

Type
GIT
Repo
https://github.com/boringproxy/boringproxy
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.10.0"
        }
    ]
}

Affected versions

v0.*
v0.1.0
v0.1.1
v0.10.0
v0.4.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.8.1
v0.8.2
v0.9.0
v0.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70615.json"