VYPR

boringproxy

by Boringproxy

CVEs (1)

  • CVE-2026-70615Aug 5, 2026
    risk 0.00cvss epss

    boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in…