
🚨 boringproxy SSH Injection — CVSS 9.9 CVE-2026-70615: Newline injection allows authenticated low-privilege users to inject SSH keys and gain persistent root access. Update to 0.10.1 NOW. → http://threataft.com/articles/boringproxy-cve-2026-70615 #cybersecurity #infosec #boringproxy #SSH #ThreatIntel
Post summary
A newline injection flaw in boringproxy (CVE‑2026‑70615) lets low‑privilege users inject SSH keys to achieve persistent root access; the 0.10.1 update now provides a patch.
