ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › API Gateway resilience suite

Layer 7 · API Gateways & Edge Ingress

API Gateway Resilience Suite

Targeted resilience checks evaluating authentication cache churn, LuaJIT request memory starvation, route matching regex algorithmic complexity, SpEL expression stalls, JSON schema validation bounds, and CircuitBreaker state leaks across modern API Gateways.

Target Kong, APISIX, Spring, Tyk, KrakenD Layer L7 Techniques 10 simulations Access Self-service / Quote

On this page

  1. Suite Overview
  2. Kong Token Parsing Panic (CVE-2026-18675)
  3. Kong LuaJIT Memory Starvation
  4. APISIX ForwardAuth Overflow (CVE-2026-31908)
  5. APISIX Regex Route Match CPU Burn
  6. Spring Cloud Gateway SpEL DoS (CVE-2026-41850)
  7. Spring Cloud Gateway Netty Buffer Starvation
  8. Tyk JSON Schema Validation DoS
  9. Tyk Auth Session Cache Churn
  10. KrakenD JOSE Header Memory (CVE-2025-30204)
  11. KrakenD CircuitBreaker State Leak (CVE-2026-13649)
  12. Safe Execution
  13. Related simulations

Suite Overview

API Gateways authenticate, rate-limit, transform, and route traffic to backend microservices. Because they execute middleware logic (Lua, Java/Reactor, Go) on every request, adversaries exploit algorithmic complexity in regex routers, token decoders, and schema validators to degrade throughput without needing raw volumetric bandwidth.

Kong Data Plane Token Parsing Panic (CVE-2026-18675)

cve_2026_18675 — Sends requests with malformed JWT kid header types to test Kong token verification error boundaries against runtime worker panics.

Kong LuaJIT Request Context Memory Starvation (kong_lua_table_exhaustion)

kong_lua_table_exhaustion — Floods requests with high-cardinality headers and cookies to test Kong OpenResty / LuaJIT context table (ngx.ctx) memory allocation bounds.

Apache APISIX ForwardAuth Header Overflow (CVE-2026-31908)

cve_2026_31908 — Sends requests with header injection sequences to test APISIX forward-auth plugin buffer reclamation and recursion limits.

Apache APISIX Regex Route Match CPU Burn (apisix_route_regex_burn)

apisix_route_regex_burn — Generates path permutations targeting complex route regex rules to evaluate APISIX radixtree routing evaluation CPU bounds.

Spring Cloud Gateway SpEL Algorithmic DoS (CVE-2026-41850)

cve_2026_41850 — Sends requests with crafted query and header tokens to test Spring Cloud Gateway SpEL predicate evaluation CPU limits.

Spring Cloud Gateway Netty Buffer Starvation (spring_cloud_gateway_netty_stall)

spring_cloud_gateway_netty_stall — Drips slow HTTP body streams across concurrent connections to evaluate Reactor Netty byte buffer pool reclamation.

Tyk JSON Schema Validation Complexity DoS (tyk_schema_validation_exhaustion)

tyk_schema_validation_exhaustion — Sends deeply nested JSON payloads to test Tyk JSON schema validation middleware CPU bounds and memory limits.

Tyk Auth Session Cache Churn (tyk_token_session_churn)

tyk_token_session_churn — Floods API endpoints with randomized bearer tokens and keys to evaluate Tyk auth cache-miss handling and Redis worker throughput.

KrakenD JOSE Header Memory Exhaustion (CVE-2025-30204)

cve_2025_30204 — Sends requests with oversized, fragmented JOSE header blocks to test KrakenD stateless JWT unmarshaling memory bounds.

KrakenD CircuitBreaker State Resource Leak (CVE-2026-13649)

cve_2026_13649 — Probes endpoints under high-frequency error state transitions to evaluate KrakenD CircuitBreaker state table resource reclamation.

Safe Execution

All simulations are bounded by verified domain controls and real-time origin health checks.

Related simulations

HTTP flood test Simulate an HTTP request flood against infrastructure you own: bounded Layer 7 requests to a path you choose reveal how your stack holds up. GraphQL complexity & depth test Simulate adversarial GraphQL depth and complexity bursts against your API: test AST depth analyzers, query cost limits and resolver budgets. HTTP/2 Rapid Reset test (CVE‑2023‑44487) Test your servers against HTTP/2 Rapid Reset (CVE-2023-44487): open and instantly cancel HTTP/2 streams against real HTTP/2 to confirm you are patched.

Validate your API Gateway resilience against adversarial loads.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA