ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › Runtime resilience suite

Layer 7 · Language Runtimes · Node.js, Go, Python, Caddy

Application Runtime Resilience Suite

Simulates runtime-specific failure modes across Node.js (http2, undici, async_hooks), Go (net/http, crypto/tls), Python (aiohttp, asyncio, EngineIO), and Caddy/quic-go to test parser safety and memory limits.

Target Node.js, Go, Python, Caddy Layer L7 Techniques 17 simulations Access Self-service / Quote

On this page

  1. Suite Overview
  2. Node.js Resilience Checks
  3. Go net/http & TLS Checks
  4. Python aiohttp & EngineIO Checks
  5. Caddy HTTP/3 QPACK Checks
  6. Safe Execution
  7. Related simulations

Suite Overview

Modern applications frequently expose runtime standard libraries (Node.js, Go, Python asyncio) directly to ingress traffic without intermediate reverse proxies. This suite evaluates whether underlying runtime parsers, asynchronous event loops, and header decoders maintain stability under adversarial payload structures.

Node.js Resilience Checks

  • cve_2024_22019 — Node.js Chunk Extension Loop: Tests chunk parser evaluation bounds under endless extension tokens.
  • cve_2024_22020 — Node.js HTTP/2 CONTINUATION Leak: Evaluates memory pool deallocation on unclosed CONTINUATION frames.
  • cve_2024_38360 — Node.js Undici Chunk Stream Leak: Tests undici HTTP client stream buffer bounding against unconsumed responses.
  • cve_2025_59465 — Node.js HTTP/2 Malformed HEADERS Crash: Streams malformed HTTP/2 HEADERS frames with invalid HPACK data to verify error boundary safety.
  • cve_2025_59466 — Node.js Async Hooks Stack Exhaustion: Sends nested asynchronous callback request bursts to verify async_hooks call-stack limits.
  • cve_2026_56846 — Node.js H2 Header Memory Limit Bypass: Streams fragmented HTTP/2 header blocks to test maxSessionMemory enforcement.

Go net/http & TLS Checks

  • cve_2024_27983 — Go net/http CONTINUATION CPU Load: Tests Go HTTP/2 server frame decoding CPU bounds.
  • cve_2024_24790 — Go net/netip Address Loop Bypass: Evaluates netip parsing under malformed IPv4/IPv6 address strings.
  • cve_2025_58186 — Go net/http Cookie Fragment Amplification: Sends requests with hundreds of tiny Cookie header fragments to test Go net/http memory bounds.
  • cve_2025_61729 — Go TLS Hostname Verification CPU: Probes Go crypto/tls certificate error formatting CPU consumption under malformed handshakes.

Python aiohttp & EngineIO Checks

  • cve_2024_23334 — Python aiohttp Path Evaluation Hang: Tests path normalization evaluation bounds under traversal tokens.
  • cve_2024_27306 — Python aiohttp Header Folding Desync: Probes aiohttp HTTP header parsing under obsolete multiline header folding.
  • cve_2025_69228 — Python aiohttp Multipart POST Stall: Streams chunked multipart POST bodies with micro-delays to test event loop bounds.
  • cve_2025_69230 — Python aiohttp Cookie Storm Logging DoS: Sends high-frequency streams of malformed cookies to test logging I/O backpressure.
  • cve_2025_69223 — Python aiohttp Auto Decompress Bomb: Sends compressed payloads to evaluate auto_decompress memory expansion ceilings.
  • cve_2026_69244 — Python aiohttp Parser Error Formatting Stall: Tests C parser error formatting bounds.
  • cve_2026_48809 — Python EngineIO WebSocket Buffer Growth: Sends continuous oversized WebSocket frames to test incoming buffer ceilings.

Caddy HTTP/3 QPACK Checks

cve_2025_4233 — Caddy / quic-go HTTP/3 QPACK Expansion: Emits HTTP/3 QPACK instruction frames to test quic-go dynamic table memory bounding.

Safe Execution

All probes run against verified customer domains with automatic error-rate and latency circuit breakers.

Related simulations

HTTP flood test Simulate an HTTP request flood against infrastructure you own: bounded Layer 7 requests to a path you choose reveal how your stack holds up. Slowloris test Simulate a Slowloris slow-HTTP attack against a domain you own: hold connections open with a trickle of keep-alive bytes to test connection exhaustion. WebSocket exhaustion test Simulate a WebSocket exhaustion attack against a domain you own: real wss handshakes held open with periodic pings to occupy per-connection state.

Validate your application runtime resilience safely.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA