CVE-2026-70615Patch

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter of the tunnel creation endpoint. Attackers can insert an unrestricted public key entry into authorized_keys to gain persistent shell access, and subsequently read cleartext credentials from the database file including all user tokens, tunnel private keys, and TLS certificates.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-06: 1Patch / Workaround · 2026-08-06: 1Technical Details · 2026-08-06: 108-06
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • ThreatAft@ThreatAft
    Patch

    🚨 boringproxy SSH Injection — CVSS 9.9 CVE-2026-70615: Newline injection allows authenticated low-privilege users to inject SSH keys and gain persistent root access. Update to 0.10.1 NOW. → http://threataft.com/articles/boringproxy-cve-2026-70615 #cybersecurity #infosec #boringproxy #SSH #ThreatIntel

    Post summary

    A newline injection flaw in boringproxy (CVE‑2026‑70615) lets low‑privilege users inject SSH keys to achieve persistent root access; the 0.10.1 update now provides a patch.

    0000059
    36 followersView on X

Explore more