AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T20:17:17.600Z and has not been modified since then. CVE-2026-70616 is a resource exhaustion vulnerability in boringproxy through 0.10.0. Any authenticated user can cause a denial-of-service condition by sending requests to the GET /loading endpoint with attacker-supplied id query parameter values [truncated]
The boringproxy service through version 0.10.0 is vulnerable to a newline injection attack. Authenticated users with low privileges and tunnel-creation permissions can inject arbitrary lines into the server account's SSH authorized_keys file. This can be achieved by supplying a percent-encoded newline character in the domain parameter of the tunnel creation endpoint. As a result, attackers can insert an u [truncated]