ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › NGINX resilience suite

Layer 7 · Web Server / Ingress · NGINX

NGINX Resilience & CVE Suite

Comprehensive resilience simulations targeting NGINX event-loop worker boundaries, HTTP/3 QUIC module CPU limits, SSI recursive depth, shared SSL session cache mutexes, and large client header pools.

Target NGINX / NGINX Plus Layer L7 & L4 Techniques 14 simulations Access Self-service / Quote

On this page

  1. Suite Overview
  2. MP4 Range Header Crash (CVE-2024-7347)
  3. QUIC ACK Range CPU Burn (CVE-2024-24989)
  4. QUIC MTU Probe Crash (CVE-2024-24990)
  5. Resolver Buffer Overwrite (CVE-2025-23014)
  6. SSI Subrequest Loop (CVE-2025-24513)
  7. Regex Map Buffer Overflow (CVE-2026-42533)
  8. HTTP/3 Frame Mismatch Crash (CVE-2026-42530)
  9. SSL OCSP Stapling Crash (CVE-2026-40701)
  10. Shared SSL Cache Contention
  11. Large Header Buffer Exhaustion
  12. Subrequest Depth Starvation
  13. Gunzip Buffer Starvation
  14. Safe Execution
  15. Related simulations

Suite Overview

NGINX handles high concurrency via asynchronous event-driven worker processes. Because workers are single-threaded event loops, blocking operations (such as regex compilation, resolver buffers, or shared memory lock contention) or worker crashes (SIGSEGV in C modules) immediately degrade all concurrent client connections sharing that worker.

MP4 Range Header Crash (CVE-2024-7347)

cve_2024_7347 — Probes NGINX ngx_http_mp4_module range header parsing to verify worker crash protection under crafted atom offsets.

QUIC ACK Range CPU Burn (CVE-2024-24989)

cve_2024_24989 — Floods crafted QUIC packets with dense, fragmented ACK range lists to evaluate NGINX ngx_http_v3_module ACK range processing CPU bounds.

QUIC MTU Probe Crash (CVE-2024-24990)

cve_2024_24990 — Sends malformed MTU discovery probe frames to test NGINX QUIC packet sizing calculations against integer underflow.

Resolver Buffer Overwrite (CVE-2025-23014)

cve_2025_23014 — Sends HTTP requests with host headers triggering complex upstream DNS resolution chains to evaluate ngx_resolver buffer bounds.

SSI Subrequest Loop (CVE-2025-24513)

cve_2025_24513 — Injects cyclical Server Side Include (SSI) directives and subrequest headers to test NGINX subrequest depth limits.

Regex Map Buffer Overflow (CVE-2026-42533)

cve_2026_42533 — Sends request headers targeting complex regex map directives to test NGINX worker buffer safety.

HTTP/3 Frame Mismatch Crash (CVE-2026-42530)

cve_2026_42530 — Sends out-of-sequence QUIC frame packets to evaluate NGINX HTTP/3 state machine crash protection.

SSL OCSP Stapling Crash (CVE-2026-40701)

cve_2026_40701 — Initiates rapid TLS handshakes with client certificate requests to test NGINX OCSP verification safety.

NGINX Shared SSL Cache Contention (nginx_ssl_session_cache_lock)

nginx_ssl_session_cache_lock — Initiates rapid concurrent TLS handshakes targeting ssl_session_cache shared:SSL:xx to evaluate worker spinlock contention under TLS load.

NGINX Large Header Buffer Exhaustion (nginx_client_header_churn)

nginx_client_header_churn — Floods headers alternating across client_header_buffer_size and large_client_header_buffers thresholds to evaluate NGINX memory pool recycling.

NGINX Subrequest Depth Starvation (nginx_subrequest_recursion)

nginx_subrequest_recursion — Sends requests triggering nested auth_request and internal redirect chains to test NGINX NGX_HTTP_MAX_SUBREQUESTS bounds.

NGINX Gunzip Buffer Starvation (nginx_gunzip_bomb_exhaustion)

nginx_gunzip_bomb_exhaustion — Sends compressed HTTP request bodies and gzip transfer streams to evaluate ngx_http_gunzip_filter_module decompressor memory safety.

Safe Execution

All probes run against verified customer infrastructure with automatic error-rate and latency circuit breakers.

Related simulations

QUIC / HTTP3 Initial flood test Simulate a QUIC / HTTP3 Initial-packet flood against a host you own: valid QUIC Initial packets over UDP, each a fresh connection the server must decrypt. SSL/TLS exhaustion test Simulate a TLS handshake flood against a domain you own to expose the CPU cost of repeated SSL/TLS negotiation and how your termination layer scales. HTTP/2 Rapid Reset test (CVE‑2023‑44487) Test your servers against HTTP/2 Rapid Reset (CVE-2023-44487): open and instantly cancel HTTP/2 streams against real HTTP/2 to confirm you are patched.

Rehearse your NGINX configuration resilience safely.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA