boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-70615HIGH
boringproxy 0.10.0 SSH authorized_keys Injection via Tunnel Creation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   N    8.5   .0022   12.2     —
AFFECTED
  Product      Versions     Fixed
  boringproxy  unspecified  —
TIMELINE
  Aug 4   Reserved by VulnCheck
  Aug 5   Published (CNA: VulnCheck)
  Aug 6   EXPLOIT PUBLISHED — CVE-2026-70615 (boringproxy). Public exploit reference added.
CWE-93 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received

Description

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter of the tunnel creation endpoint. Attackers can insert an unrestricted public key entry into authorized_keys to gain persistent shell access, and subsequently read cleartext credentials from the database file including all user tokens, tunnel private keys, and TLS certificates.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 4, 2026ReservedReserved by VulnCheck
August 5, 2026PublishedPublished (CNA: VulnCheck)
August 6, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-70615 (boringproxy). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
boringproxyboringproxy

Weaknesses

CWE-93

References (2)

Related

Authoritative record: CVE-2026-70615 at cve.org

Vendors: boringproxy

Weaknesses: CWE-93

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-70615 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.