Suite Overview
API Gateways authenticate, rate-limit, transform, and route traffic to backend microservices. Because they execute middleware logic (Lua, Java/Reactor, Go) on every request, adversaries exploit algorithmic complexity in regex routers, token decoders, and schema validators to degrade throughput without needing raw volumetric bandwidth.
Kong Data Plane Token Parsing Panic (CVE-2026-18675)
cve_2026_18675 — Sends requests with malformed JWT kid header types to test Kong token verification error boundaries against runtime worker panics.
Kong LuaJIT Request Context Memory Starvation (kong_lua_table_exhaustion)
kong_lua_table_exhaustion — Floods requests with high-cardinality headers and cookies to test Kong OpenResty / LuaJIT context table (ngx.ctx) memory allocation bounds.
Apache APISIX ForwardAuth Header Overflow (CVE-2026-31908)
cve_2026_31908 — Sends requests with header injection sequences to test APISIX forward-auth plugin buffer reclamation and recursion limits.
Apache APISIX Regex Route Match CPU Burn (apisix_route_regex_burn)
apisix_route_regex_burn — Generates path permutations targeting complex route regex rules to evaluate APISIX radixtree routing evaluation CPU bounds.
Spring Cloud Gateway SpEL Algorithmic DoS (CVE-2026-41850)
cve_2026_41850 — Sends requests with crafted query and header tokens to test Spring Cloud Gateway SpEL predicate evaluation CPU limits.
Spring Cloud Gateway Netty Buffer Starvation (spring_cloud_gateway_netty_stall)
spring_cloud_gateway_netty_stall — Drips slow HTTP body streams across concurrent connections to evaluate Reactor Netty byte buffer pool reclamation.
Tyk JSON Schema Validation Complexity DoS (tyk_schema_validation_exhaustion)
tyk_schema_validation_exhaustion — Sends deeply nested JSON payloads to test Tyk JSON schema validation middleware CPU bounds and memory limits.
Tyk Auth Session Cache Churn (tyk_token_session_churn)
tyk_token_session_churn — Floods API endpoints with randomized bearer tokens and keys to evaluate Tyk auth cache-miss handling and Redis worker throughput.
KrakenD JOSE Header Memory Exhaustion (CVE-2025-30204)
cve_2025_30204 — Sends requests with oversized, fragmented JOSE header blocks to test KrakenD stateless JWT unmarshaling memory bounds.
KrakenD CircuitBreaker State Resource Leak (CVE-2026-13649)
cve_2026_13649 — Probes endpoints under high-frequency error state transitions to evaluate KrakenD CircuitBreaker state table resource reclamation.
Safe Execution
All simulations are bounded by verified domain controls and real-time origin health checks.
← All DDoS simulations