ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › HTTP/2 CONTINUATION flood test

Layer 7 · Application · http2_continuation_flood

HTTP/2 CONTINUATION flood test

The http2_continuation_flood simulation opens an HTTP/2 request whose header block is never finished and streams CONTINUATION frames without end — the 2024 CONTINUATION-flood class (CVE-2024-27316 and related) — against a domain you own, to see whether your stack buffers header state without bound.

Layer L7 Protocol HTTP/2 Command http2_continuation_flood Access Quote on request

On this page

  1. What the CONTINUATION flood does
  2. How ddos-simulation.com simulates it safely
  3. What the test exercises
  4. When to run it
  5. How to run the test
  6. Reading the results
  7. Availability & limits
  8. FAQ
  9. Related simulations

What the CONTINUATION flood does

Disclosed in 2024, the CONTINUATION flood sends a HEADERS frame without the END_HEADERS flag and then an unbounded run of CONTINUATION frames that also never end the header block. A server that keeps appending to the header list without enforcing a limit during CONTINUATION processing allocates memory indefinitely for a request that never completes — from a single low-bandwidth connection, often without ever logging a request.

How ddos-simulation.com simulates it safely

ddos-simulation.com speaks genuine HTTP/2 to a single verified domain pinned to a public address, opens one stream, and streams fixed dummy header fragments within the domain’s rate limits. The header content is fixed and non-configurable, and the verified domain must serve HTTP/2 for the frames to reach an HTTP/2 stack.

Authorized targets only

Every run is bound to one verified domain you have proven you own. Ownership is checked over HTTPS before anything is scheduled, and running traffic against systems you do not own or are not clearly authorized to test may be unlawful. See the Acceptable Use Policy.

What the test exercises

  • Whether header-list-size limits are enforced during CONTINUATION processing
  • Per-connection memory bounds for an incomplete header block
  • How your HTTP/2 stack caps unterminated header streams
  • Proxy, load-balancer, and origin behavior under the flood
  • Recovery once the connection is closed

When to run an HTTP/2 CONTINUATION flood test

Run an HTTP/2 CONTINUATION flood test when unbounded header buffering is the failure mode you need to rule out.

  • You run HTTP/2 servers and want to confirm header-list and CONTINUATION-frame limits are enforced (CVE-2024-27316 class).
  • You've updated your HTTP/2 stack and want to verify the fix under an unfinished, endlessly-continued header block.
  • A proxy or CDN handles HTTP/2 framing and you need to confirm it caps header state before the origin.

How to run an HTTP/2 CONTINUATION flood test

  1. Verify your domain. Prove ownership over HTTPS — it is self-service and takes minutes.
  2. Add the http2_continuation_flood command to a timeline in the portal and set the rate, duration, and any concurrency limit.
  3. Set health thresholds. Choose the error-rate, latency, or status-code limits at which the test should abort itself.
  4. Run and watch. Bounded workers are provisioned minutes before start and torn down the moment the last task ends, while metrics stream live.
  5. Read the results. Review the recorded latency, status codes, and worker timeline to find where your service starts to bend.

Configure an HTTP/2 CONTINUATION flood test in the portal →

Reading the results

Resilient: Header-size and frame-count limits abort the abusive stream early, memory stays flat, and other connections are unaffected.

Under strain: Memory grows without bound as frames arrive, the process approaches out-of-memory, or connection handling stalls under the header pressure.

Availability & limits

The HTTP/2 CONTINUATION flood is priced per engagement — request a quote. Verify your domain before it runs.

Frequently asked questions

What is the CONTINUATION flood?

A 2024 class of HTTP/2 denial-of-service (CVE-2024-27316 and related) in which endless CONTINUATION frames force a server to buffer an ever-growing header block that never completes.

How is it different from Rapid Reset?

Rapid Reset churns many short-lived streams to burn CPU; the CONTINUATION flood holds one stream open and grows its header state, exhausting memory instead.

Related simulations

HTTP/2 Rapid Reset test Open and instantly cancel HTTP/2 streams to confirm you are patched against CVE-2023-44487. HTTP/2 MadeYouReset test Provoke server-sent stream resets that bypass the Rapid Reset mitigation. Slowloris test Simulate a Slowloris slow-HTTP attack against a domain you own.

Rehearse an HTTP/2 CONTINUATION flood test against infrastructure you own — bounded, monitored, and stopped the instant you have your answer.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA