


Perceptive Security
SOC/SIEM Consultancy

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject a…
Published:
4 August 2026 at 22:00:00
Alert date:
5 August 2026 at 21:03:13
Source:
nvd.nist.gov
Network Infrastructure, Identity & Access, Data Breach & Exfiltration
boringproxy through version 0.10.0 contains a critical newline injection vulnerability in its tunnel creation endpoint. Authenticated low-privileged users with tunnel-creation permissions can exploit this flaw by supplying a percent-encoded newline character in the domain parameter. This allows attackers to inject arbitrary lines into the server's SSH authorized_keys file, enabling insertion of unauthorized public keys. Successful exploitation grants persistent shell access to the server. Furthermore, attackers can subsequently read cleartext credentials from the database file, exposing all user tokens, tunnel private keys, and TLS certificates. The vulnerability represents a significant privilege escalation and credential theft risk for any deployment of the affected software.
Technical details
Mitigation steps:
Affected products:
boringproxy 0.10.0 and earlier
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-70615
https://github.com/theopaid/Remote-Code-Execution-And-Privilege-Escalation-Through-SSH-Authorized-Keys-Injection-boringproxy-/blob/master/README.md
https://www.vulncheck.com/advisories/boringproxy-ssh-authorized-keys-injection-via-tunnel-creation
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
