ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › Envoy resilience suite

Layer 7 · Cloud-Native Proxy · Envoy

Envoy Proxy Resilience & CVE Suite

Simulates Envoy Proxy filter chain crashes, downstream stream reset resource exhaustion, TCP proxy tunnel synchronization, and recursive JSON destructor depth limits.

Target Envoy Proxy Layer L7 Techniques 9 simulations Access Self-service / Quote

On this page

  1. Suite Overview
  2. HTTP/2 Reset Flood (CVE-2024-36137)
  3. HTTP/1 Chunk Header Buffer (CVE-2024-36138)
  4. ReDoS Filter Saturation (CVE-2024-42475)
  5. TCP Connection Pool Crash (CVE-2025-62409)
  6. CONNECT Tunnel Desync (CVE-2025-64763)
  7. ext_proc Local Reply Crash (CVE-2025-30157)
  8. Deep JSON Stack Overflow (CVE-2026-48042)
  9. Router 303 Redirect Crash (CVE-2026-47221)
  10. OAuth2 Async In-Flight Crash (CVE-2026-48090)
  11. Safe Execution
  12. Related simulations

Suite Overview

Envoy is standard in Kubernetes service meshes (Istio, Linkerd) and edge ingress controllers. This suite evaluates whether your Envoy filters, worker threads, and memory pools withstand adversarial stream manipulation and protocol deviations.

Envoy HTTP/2 Reset Flood (CVE-2024-36137)

cve_2024_36137 — Validates Envoy downstream stream reset flood protection against worker memory and event queue exhaustion.

Envoy HTTP/1 Chunk Header Buffer (CVE-2024-36138)

cve_2024_36138 — Tests Envoy HTTP/1 codec parsing under malformed chunked transfer encodings.

Envoy ReDoS Filter Saturation (CVE-2024-42475)

cve_2024_42475 — Evaluates Envoy regex route matching and filter chains against algorithmic complexity stalls.

Envoy TCP Connection Pool Crash (CVE-2025-62409)

cve_2025_62409 — Evaluates Envoy TCP connection pool state transitions against null pointer dereferences.

Envoy CONNECT Tunnel Desync (CVE-2025-64763)

cve_2025_64763 — Tests Envoy TCP proxy mode CONNECT early-data stream synchronization limits.

Envoy ext_proc Local Reply Crash (CVE-2025-30157)

cve_2025_30157 — Probes Envoy ext_proc filter crash safety on local replies during aborted client handshakes.

Envoy Deep JSON Object Stack Overflow (CVE-2026-48042)

cve_2026_48042 — Sends HTTP payloads with deeply nested JSON arrays/objects to evaluate Envoy JSON destructor stack bounds.

Envoy Router 303 Redirect NULL Crash (CVE-2026-47221)

cve_2026_47221 — Sends bodyless requests provoking HTTP 303 redirects to verify Envoy router filter null pointer handling.

Envoy OAuth2 Async In-Flight Exchange Crash (CVE-2026-48090)

cve_2026_48090 — Triggers in-flight async OAuth2 token exchange cancellation to test Envoy worker thread safety.

Safe Execution

Simulations are executed with live origin monitoring and automatic termination on latency or error spikes.

Related simulations

HTTP/2 Rapid Reset test (CVE‑2023‑44487) Test your servers against HTTP/2 Rapid Reset (CVE-2023-44487): open and instantly cancel HTTP/2 streams against real HTTP/2 to confirm you are patched. HTTP/2 CONTINUATION flood test Test your servers against the HTTP/2 CONTINUATION flood (CVE-2024-27316 class): an unterminated header block streamed as endless CONTINUATION frames. SSL/TLS exhaustion test Simulate a TLS handshake flood against a domain you own to expose the CPU cost of repeated SSL/TLS negotiation and how your termination layer scales.

Verify your Envoy Proxy deployment resilience.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA