top of page
perceptive_background_267k.jpg

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject a…

Published:

5 August 2026 at 00:00:00

Alert date:

5 August 2026 at 23:03:13

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Identity & Access, Data Breach & Exfiltration

boringproxy through version 0.10.0 contains a critical newline injection vulnerability in its tunnel creation endpoint. Authenticated low-privileged users with tunnel-creation permissions can exploit this flaw by supplying a percent-encoded newline character in the domain parameter. This allows attackers to inject arbitrary lines into the server's SSH authorized_keys file, enabling insertion of unauthorized public keys. Successful exploitation grants persistent shell access to the server. Furthermore, attackers can subsequently read cleartext credentials from the database file, exposing all user tokens, tunnel private keys, and TLS certificates. The vulnerability represents a significant privilege escalation and credential theft risk for any deployment of the affected software.

Technical details

Mitigation steps:

Affected products:

boringproxy 0.10.0 and earlier

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page