CPE
low
advisory
Service Exhaustion via Stalled TLS ALPN Handshakes
1 TTP 2 CVEs 2 IOCsAttackers are exploiting unpatched TLS listeners by flooding them with incomplete ACME ALPN handshakes to exhaust server-side resources like goroutines and worker threads.
PoC
Traefik +7
1t
2c
2i
updated
high
advisory
Traefik ForwardAuth Authentication Bypass via Header Spoofing
2 rules 1 TTP 2 CVEsTraefik's `ForwardAuth` and snippet-based authentication middleware has a high severity authentication bypass vulnerability because it does not sanitize header aliases with underscores, allowing attackers to spoof trust context and bypass authentication on protected routes.
PoC
Traefik +1
authentication-bypass
header-injection
forwarded-headers
2r
1t
2c
updated