hub · compare
/xml
well-formed XML — honest declaration, correct nesting, no entity declarations, no external references
chaos.catastrophic.ioGET /xml
Returns XML documents with parser-attack or well-formedness flaws. Targets SOAP, B2B, RSS/sitemap, and config-file ingestion pipelines. Default mode is visible misnesting; other modes cover entity-expansion DoS, external-entity references, and declaration-vs-body encoding mismatch.
modes:
mismatched-tags
billion-laughs
xxe-external
encoding-mismatchnot.catastrophic.ioGET /xml
well-formed XML — honest declaration, correct nesting, no entity declarations, no external references
Build against not.catastrophic.io/xml, then
flip the hostname to chaos.catastrophic.io to exercise the chaos.