Preliminary research
Slow JSON Stream: A Low-Bandwidth Denial-of-Service Attack Against HTTP APIs with JSON Request Bodies
AI-collected research leads through 1 October 2026, including a bounded September review of selected social and community sources. Unranked, incomplete, not community-vetted, and subject to change.
A client keeps an HTTP/1.1 chunked JSON body syntactically open while sending one byte per second, tying up framework body readers that lack effective request-body timeouts. Tests across 41 framework and infrastructure targets report that 90% are vulnerable under default configuration.
Record
- Researcher
- Daniel Alfocea and @ggdaniel
- Published by
- Daniel Alfocea
- Date
- Topic
- HTTP
In the archive
Related sources
- Slow JSON Stream testbed and attack tool Repository
Tags
This page is the archive's own catalogue record. The research is the work of Daniel Alfocea and @ggdaniel, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .