logo

OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload

ID: 6ca56f15-e44f-5672-9ec5-060d7c280460

STIX ID: report--6ca56f15-e44f-5672-9ec5-060d7c280460

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

Author: Eswar

...
...

A newly disclosed OpenSSL DoS vulnerability dubbed “HollowByte” lets a remote unauthenticated attacker trigger unvalidated buffer pre-allocation from an 11-byte payload, causing heavy heap fragmentation, persistent RSS growth, and service disruption across many OpenSSL-using products; OpenSSL fixed the issue by switching to incremental buffer growth in v4.0.1 with backports, and organizations should prioritize upgrading internet-facing systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.