Skip to content
Threat Feed
low advisory PoC updated

Service Exhaustion via Stalled TLS ALPN Handshakes

Attackers are exploiting unpatched TLS listeners by flooding them with incomplete ACME ALPN handshakes to exhaust server-side resources like goroutines and worker threads.

What's new

  • 1. new product Aug 6, 21:30 via ghsa
  • 2. new IOCs Aug 6, 21:30 via ghsa
  • 3. poc_available; traefik version v3.7.0 <= v3.7.7 Aug 6, 21:30 via ghsa

This threat involves the abuse of the acme-tls/1 ALPN extension to trigger denial-of-service conditions against TLS-enabled reverse proxies. Attackers initiate high volumes of TLS connections advertising the acme-tls/1 extension, a protocol intended only for ACME TLS-ALPN-01 certificate validation, and deliberately stall the handshake process. By failing to complete the handshake, the attacker forces the destination service to maintain open connection states, effectively exhausting available goroutines, worker threads, or accept queue depths. This exploitation pattern is specifically documented as a technique to target CVE-2026-22045, which affects services like Traefik that lack adequate handshake timeout enforcement. When performed at scale, this resource exhaustion results in a denial-of-service (DoS) for legitimate users. Defenders should monitor for repeated incomplete TLS sessions originating from non-authorized sources to identify exploitation attempts against edge infrastructure.

Impact

Successful exploitation leads to a denial of service on internet-facing reverse proxies and web application load balancers, impacting service availability. Affected infrastructure includes common reverse proxies such as Traefik, nginx, HAProxy, and Caddy. If handshake timeouts are not correctly configured, a relatively low-volume flood can exhaust server resources, causing service instability or total outage for the host.

Recommendation

Prioritize hardening of all internet-facing TLS listeners to prevent resource exhaustion.

  • Upgrade Traefik and other reverse proxies to versions that explicitly address CVE-2026-22045 and related handshake-timeout vulnerabilities.
  • Enforce strict ssl_handshake_timeout settings at the listener level to bound the duration any connection can remain in a pending state.
  • Rate-limit inbound TLS connections per source IP at the network perimeter to mitigate the impact of connection-flooding attacks.
  • Configure the Elastic Agent network_traffic integration with include_detailed_fields: true to ensure visibility into ALPN extension fields.
  • Suppress noise by creating allowlists for known ACME Certificate Authority IP ranges (e.g., Let's Encrypt, ZeroSSL, Buypass) and internal certificate renewal agents.

Indicators of compromise

2

hash_sha256

TypeValue
hash_sha2565c8ff19144683f862c04e8ac01893e8cd94a3519d3d9ca3e6fbd0a7de73261ba
hash_sha256dbd809b1de85d86d0718c80bedbaabd9aebaa3c6697f9e986ab5f387f4196cb7