Kong API Gateway's internal /status endpoint is publicly accessible either directly or via IP restriction bypass using spoofed headers. The endpoint exposes server metrics including active connections, request counts, database reachability, worker Lua VM memory usage, and shared dictionary allocation details.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view