vulns.co
/
GKData.io MCP

USENIX Association · 1 min read

STEK Sharing is Not Caring: Bypassing TLS Authentication in Web Servers using Session Tickets

Studies a cross-layer authentication failure: shared TLS session-ticket infrastructure can preserve cryptographic session state without preserving the intended virtual-host identity and client-authentication policy. The authors connect that mismatch to inconsistent isolation during session resumption.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

Document which authenticated identities and policy decisions must survive connection resumption in an owned hosting design. Review library contracts and remediation evidence for preserved identity context rather than assuming that an accepted session ticket establishes all application authority.

Before reading

  • TLS certificates and session resumption
  • Virtual hosting and application routing

Context and limits

  • Measurements and vendor observations are historical, not evidence of present exposure.
  • The study describes sampling and configuration limits; its findings are not exhaustive.
  • This record summarizes identity invariants and countermeasures, not the paper’s testing procedures.

Sources and provenance

  1. STEK Sharing is Not Caring: Bypassing TLS Authentication in Web Servers using Session Tickets USENIX Association · reviewed 2026-10-03
  2. Publisher-hosted proceedings paper USENIX Association · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software