ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › HAProxy resilience suite

Layer 7 · High-Performance Load Balancer · HAProxy

HAProxy Resilience & CVE Suite

Evaluates HAProxy ring buffer reclamation, HTTP/2 multiplexing limits, mjson parser query depth, and QUIC packet underflow loop handling under load.

Target HAProxy Layer L7 & L4 Techniques 4 simulations Access Self-service / Quote

On this page

  1. Suite Overview
  2. H2-H1 Multiplexing Leak (CVE-2024-45506)
  3. HTTP/2 Trailer Frame Loop (CVE-2024-45507)
  4. mjson Query Complexity DoS (CVE-2025-11230)
  5. QUIC Packet Underflow Loop (CVE-2026-26080)
  6. Safe Execution
  7. Related simulations

Suite Overview

HAProxy is widely deployed for ultra-low-latency load balancing and TLS termination. This suite verifies memory buffer pool reclamation, multiplexer deallocation, and parser crash safety.

HAProxy H2-H1 Multiplexing Leak (CVE-2024-45506)

cve_2024_45506 — Tests HAProxy HTTP/2 connection multiplexer buffer reclamation during rapid stream aborts.

HAProxy HTTP/2 Trailer Frame Loop (CVE-2024-45507)

cve_2024_45507 — Evaluates HAProxy ring buffer management under fragmented HTTP payload and trailer frame streaming.

HAProxy mjson Query Complexity DoS (CVE-2025-11230)

cve_2025_11230 — Sends deeply nested or oversized numeric JSON query payloads to test HAProxy mjson parser resilience.

HAProxy QUIC Packet Underflow Loop (CVE-2026-26080)

cve_2026_26080 — Sends truncated QUIC packet headers to test HAProxy QUIC packet parsing loop bounds and underflow defense.

Safe Execution

All simulations are run with real-time latency sampling and automatic abort triggers.

Related simulations

TCP connection flood test Simulate a TCP connection flood against a domain you own: full, unspoofed handshakes completed and dropped at a set rate to flood the accept path. Slowloris test Simulate a Slowloris slow-HTTP attack against a domain you own: hold connections open with a trickle of keep-alive bytes to test connection exhaustion. SSL/TLS exhaustion test Simulate a TLS handshake flood against a domain you own to expose the CPU cost of repeated SSL/TLS negotiation and how your termination layer scales.

Verify your HAProxy configuration resilience.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA