ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › Apache resilience suite

Layer 7 · Web Server · Apache HTTP Server

Apache HTTP Server Resilience & CVE Suite

A dedicated suite of authorized resilience simulations evaluating Apache HTTP Server and Apache HttpCore module stability, error boundaries, memory pooling, and mitigation defenses against known CVE regression vectors.

Target Apache HTTP Server / HttpCore Layer L7 Techniques 9 simulations Access Self-service / Quote

On this page

  1. Suite Overview
  2. mod_rewrite Substitution (CVE-2024-38477)
  3. mod_proxy NULL Dereference (CVE-2024-38474)
  4. mod_rewrite Loop (CVE-2024-38476)
  5. mod_proxy Split-URI Crash (CVE-2024-39338)
  6. mod_rewrite Target Bypass (CVE-2024-39573)
  7. Windows UNC Path Crash (CVE-2024-38472)
  8. mod_lua Handler Hang (CVE-2024-40898)
  9. HTTP/2 Bomb Memory Exhaustion (CVE-2026-49975)
  10. HttpCore HPACK Decoder Overflow (CVE-2026-54428)
  11. Safe Execution & Monitoring
  12. Related simulations

Suite Overview

Apache HTTP Server powers critical web and reverse proxy workloads worldwide. This suite evaluates whether your Apache instances, custom module configurations, and reverse proxy chains maintain availability when probed with edge-case URI encodings, recursive rewrite rules, and HPACK decompression sequences.

Apache mod_rewrite Crash (CVE-2024-38477)

cve_2024_38477 — Tests mod_rewrite substitution handling under encoded characters and null-byte variations to verify worker crash protection.

Apache mod_proxy NULL Dereference (CVE-2024-38474)

cve_2024_38474 — Probes mod_proxy backend forwarding when handling atypical request URI encodings to confirm pointer validation safety.

Apache mod_rewrite Loop (CVE-2024-38476)

cve_2024_38476 — Tests internal subrequest and redirect iteration limits in mod_rewrite to prevent CPU exhaustion loops.

Apache mod_proxy Split-URI Crash (CVE-2024-39338)

cve_2024_39338 — Evaluates mod_proxy split-URI parsing logic under crafted path delimiters.

Apache mod_rewrite Target Bypass (CVE-2024-39573)

cve_2024_39573 — Verifies mod_rewrite handler bounds when processing non-canonical filesystem paths.

Apache Windows UNC Path Crash (CVE-2024-38472)

cve_2024_38472 — Probes Windows Apache installations against UNC network path dereference vulnerabilities.

Apache mod_lua Handler Hang (CVE-2024-40898)

cve_2024_40898 — Tests mod_lua script execution timeout enforcement and memory release under stalled request handlers.

Apache HTTP/2 Bomb Memory Exhaustion (CVE-2026-49975)

cve_2026_49975 — Chains HPACK dynamic compression inflation with flow-control holds to evaluate Apache mod_http2 memory limits.

Apache HttpCore HPACK Decoder Overflow (CVE-2026-54428)

cve_2026_54428 — Streams crafted HPACK dynamic table state modifications to test Apache HttpComponents decoder buffer bounds.

Safe Execution & Monitoring

All simulations are run against verified target domains with automated origin health monitoring. If response latency exceeds your configured threshold, the simulation aborts immediately.

Related simulations

Slowloris test Simulate a Slowloris slow-HTTP attack against a domain you own: hold connections open with a trickle of keep-alive bytes to test connection exhaustion. HTTP/2 CONTINUATION flood test Test your servers against the HTTP/2 CONTINUATION flood (CVE-2024-27316 class): an unterminated header block streamed as endless CONTINUATION frames. SSL/TLS exhaustion test Simulate a TLS handshake flood against a domain you own to expose the CPU cost of repeated SSL/TLS negotiation and how your termination layer scales.

Rehearse Apache resilience against infrastructure you own.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA