VYPR

boringproxy

by Boringproxy

CVEs (1)

  • CVE-2026-70615CriAug 5, 2026
    risk 0.64cvss 9.9epss 0.00

    boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in…