logo

HollowByte: 11-Byte Payload Triggers Memory Bloat DoS on OpenSSL Servers

ID: 53823eef-cfc9-5910-af6c-003db16ee7ca

STIX ID: report--53823eef-cfc9-5910-af6c-003db16ee7ca

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

...
...

HollowByte is an OpenSSL denial-of-service vulnerability that allows an unauthenticated attacker to trigger excessive memory allocation with a crafted 11‑byte TLS packet, potentially causing processes to be killed or become unresponsive; operators should urgently apply OpenSSL patches, restart affected services, and implement rate limiting, connection throttling, and TLS termination behind proxies or CDNs as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.