What is CVE-2026-70616?
CVE-2026-70616 is a resource exhaustion vulnerability in boringproxy up to version 0.10.0 that allows any authenticated user to permanently exhaust server file descriptors, goroutines, and memory by sending requests to the GET /loading endpoint with attacker-supplied id query parameter values. To mitigate this, it is crucial to immediately update boringproxy to the latest patched version.
Azərbaycanca: CVE-2026-70616 boşluğu boringproxy-in 0.10.0 və əvvəlki versiyalarında autentifikasiya olunmuş istənilən istifadəçiyə xüsusi `id` sorğu parametri ilə `/loading` endpoint-inə sorğu göndərərək serverin fayl deskriptorlarını, gorutinlərini və yaddaşını daimi olaraq tükəndirməyə imkan verir. Bu resurs tükənməsi zəifliyindən qorunmaq üçün boringproxy-i ən son təhlükəsizlik yeniləməsi ilə dərhal yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which versions of boringproxy are affected by CVE-2026-70616?
CVE-2026-70616 affects boringproxy up to version 0.10.0.
How can I mitigate the CVE-2026-70616 vulnerability?
To mitigate this vulnerability, it is recommended to immediately update boringproxy to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.