ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › Varnish resilience suite

Layer 7 · Caching Accelerator · Varnish Cache

Varnish Cache Resilience & CVE Suite

Simulates workspace memory allocation boundaries, HTTP/2 transport upgrade buffer splitting, HeaderPlus workspace overflows, and broken flow-control window thread starvation against Varnish Cache instances.

Target Varnish Cache / Enterprise Layer L7 Techniques 4 simulations Access Self-service / Quote

On this page

  1. Suite Overview
  2. HTTP/1 Linger Pipelining (CVE-2026-40396)
  3. HTTP/2 Upgrade Workspace Exhaustion (CVE-2026-40394)
  4. HeaderPlus Workspace Overflow (CVE-2026-40395)
  5. HTTP/2 Broke Window Flow-Control (CVE-2024-30156)
  6. Safe Execution
  7. Related simulations

Suite Overview

Varnish Cache uses dedicated per-thread and per-session workspaces (workspace_client, workspace_backend). When unexpected pipelining or header expansion exceeds the fixed workspace boundary without proper error handling, worker threads can trigger assertions or panic restarts.

HTTP/1 Linger Pipelining Workspace Overflow (CVE-2026-40396)

cve_2026_40396 — Sends pipelined HTTP/1 requests interleaved with linger delays to test Varnish workspace boundary and assertion safety.

HTTP/2 Upgrade Speculative Workspace Exhaustion (CVE-2026-40394)

cve_2026_40394 — Sends Upgrade: h2c with trailing pipelined HTTP/2 preface payload to test Varnish transport upgrade buffer splitting safety.

Varnish Enterprise HeaderPlus Workspace Overflow (CVE-2026-40395)

cve_2026_40395 — Sends requests with high-cardinality header arrays to test Varnish vmod_headerplus / req0 workspace bounds.

Varnish HTTP/2 Broke Window Flow-Control Starvation (CVE-2024-30156)

cve_2024_30156 — Opens concurrent HTTP/2 streams with minimal flow-control window increments to evaluate Varnish worker thread release under credit exhaustion.

Safe Execution

All simulations run against your verified domain with real-time health checks and automatic circuit-breaker abortion.

Related simulations

HTTP flood test Simulate an HTTP request flood against infrastructure you own: bounded Layer 7 requests to a path you choose reveal how your stack holds up. HTTP/2 Rapid Reset test (CVE‑2023‑44487) Test your servers against HTTP/2 Rapid Reset (CVE-2023-44487): open and instantly cancel HTTP/2 streams against real HTTP/2 to confirm you are patched. Slowloris test Simulate a Slowloris slow-HTTP attack against a domain you own: hold connections open with a trickle of keep-alive bytes to test connection exhaustion.

Test your Varnish Cache tuning and resilience safely.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA