ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | Mar 26, 2024 | Mar 23, 2022 |
| Amazon Linux Ami 2 | — | Upgrade nginx-mod-http-perlUpgrade nginx-mod-mailUpgrade nginxUpgrade nginx-mod-http-image-filterUpgrade vsftpd-sysvinitUpgrade nginx-mod-http-geoipUpgrade nginx-all-modulesUpgrade nginx-filesystemUpgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filterUpgrade vsftpdUpgrade nginx-debuginfoUpgrade vsftpd-debuginfo | Sep 28, 2023 | Mar 23, 2022 |
| Amazon_linux_2023 | — | Upgrade sendmail-debuginfoUpgrade nginxUpgrade vsftpd-debuginfoUpgrade nginx-all-modulesUpgrade nginx-core-debuginfoUpgrade sendmail-milter-develUpgrade nginx-filesystemUpgrade vsftpd-debugsourceUpgrade sendmail-debugsourceUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-mailUpgrade sendmail-docUpgrade vsftpdUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-mail-debuginfoUpgrade nginx-coreUpgrade nginx-mod-http-perlUpgrade nginx-mod-streamUpgrade sendmail-cfUpgrade sendmailUpgrade nginx-debugsourceUpgrade nginx-debuginfoUpgrade sendmail-milterUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-develUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-stream-debuginfoUpgrade sendmail-milter-debuginfo | Feb 17, 2025 | Jun 9, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 23, 2022 |
| Debian | — | Upgrade nginxUpgrade sendmailUpgrade vsftpd | Nov 24, 2022 | Mar 23, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade nginx | Oct 26, 2021 | Sep 24, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filterUpgrade nginx-filesystemUpgrade nginx-all-modulesUpgrade nginx-mod-mailUpgrade nginxUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-image-filter | Sep 29, 2021 | Sep 24, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade nginxUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-mailUpgrade nginx-mod-http-perlUpgrade nginx-all-modulesUpgrade nginx-mod-streamUpgrade nginx-filesystemUpgrade nginx-mod-http-xslt-filter | Sep 24, 2021 | Sep 24, 2021 |
| Nginx | — | Upgrade to nginx version 1.21.0 | Feb 10, 2023 | Mar 23, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 23, 2022 |
| Suse | — | Upgrade nginxUpgrade nginx-sourceUpgrade vim-plugin-nginxUpgrade vsftpd | Oct 26, 2022 | Mar 23, 2022 |
| Ubuntu | — | Upgrade nginx-light (Ubuntu Pro)Upgrade nginx-fullUpgrade nginx-coreUpgrade vsftpdUpgrade nginx-extras (Ubuntu Pro)Upgrade nginx-core (Ubuntu Pro)Upgrade nginx-lightUpgrade nginx-extrasUpgrade libnginx-mod-http-lua | Apr 13, 2022 | Mar 23, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 23, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub