online / endpoints 139 / categories 19 / rate 60/min/ip /
hub · compare

/xml

well-formed XML — honest declaration, correct nesting, no entity declarations, no external references

chaos chaos.catastrophic.io

GET /xml

Returns XML documents with parser-attack or well-formedness flaws. Targets SOAP, B2B, RSS/sitemap, and config-file ingestion pipelines. Default mode is visible misnesting; other modes cover entity-expansion DoS, external-entity references, and declaration-vs-body encoding mismatch.

modes: mismatched-tags billion-laughs xxe-external encoding-mismatch
control not.catastrophic.io

GET /xml

well-formed XML — honest declaration, correct nesting, no entity declarations, no external references

Build against not.catastrophic.io/xml, then flip the hostname to chaos.catastrophic.io to exercise the chaos.