logo

OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes

ID: 5a8ce6ce-7191-5aba-b4de-dc3b32928fc2

STIX ID: report--5a8ce6ce-7191-5aba-b4de-dc3b32928fc2

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Guru Baran

...
...

A newly disclosed OpenSSL denial-of-service vulnerability, dubbed "HollowByte," enables remote unauthenticated attackers to force excessive pre-allocated memory during the TLS handshake via a crafted 11-byte payload, leading to memory fragmentation and server OOM conditions; Okta Red Team testing demonstrated significant RAM exhaustion on NGINX, and OpenSSL mitigated the issue by switching to incremental buffer growth (merged into v4.0.1 and backported to 3.6.3, 3.5.7, 3.4.6, 3.0.21) but treated the change as a hardening improvement without a CVE, increasing the risk that some deployments may remain unpatched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.