Suite Overview
Envoy is standard in Kubernetes service meshes (Istio, Linkerd) and edge ingress controllers. This suite evaluates whether your Envoy filters, worker threads, and memory pools withstand adversarial stream manipulation and protocol deviations.
Envoy HTTP/2 Reset Flood (CVE-2024-36137)
cve_2024_36137 — Validates Envoy downstream stream reset flood protection against worker memory and event queue exhaustion.
Envoy HTTP/1 Chunk Header Buffer (CVE-2024-36138)
cve_2024_36138 — Tests Envoy HTTP/1 codec parsing under malformed chunked transfer encodings.
Envoy ReDoS Filter Saturation (CVE-2024-42475)
cve_2024_42475 — Evaluates Envoy regex route matching and filter chains against algorithmic complexity stalls.
Envoy TCP Connection Pool Crash (CVE-2025-62409)
cve_2025_62409 — Evaluates Envoy TCP connection pool state transitions against null pointer dereferences.
Envoy CONNECT Tunnel Desync (CVE-2025-64763)
cve_2025_64763 — Tests Envoy TCP proxy mode CONNECT early-data stream synchronization limits.
Envoy ext_proc Local Reply Crash (CVE-2025-30157)
cve_2025_30157 — Probes Envoy ext_proc filter crash safety on local replies during aborted client handshakes.
Envoy Deep JSON Object Stack Overflow (CVE-2026-48042)
cve_2026_48042 — Sends HTTP payloads with deeply nested JSON arrays/objects to evaluate Envoy JSON destructor stack bounds.
Envoy Router 303 Redirect NULL Crash (CVE-2026-47221)
cve_2026_47221 — Sends bodyless requests provoking HTTP 303 redirects to verify Envoy router filter null pointer handling.
Envoy OAuth2 Async In-Flight Exchange Crash (CVE-2026-48090)
cve_2026_48090 — Triggers in-flight async OAuth2 token exchange cancellation to test Envoy worker thread safety.
Safe Execution
Simulations are executed with live origin monitoring and automatic termination on latency or error spikes.
← All DDoS simulations