logo

HollowByte: 11-Byte Payload Triggers OpenSSL Server Memory Exhaustion

ID: 5a649ae4-7530-5811-aeef-ef6ac1a27dcb

STIX ID: report--5a649ae4-7530-5811-aeef-ef6ac1a27dcb

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-07-19

Date Updated: 2026-07-19

...
...

**HollowByte** is a newly disclosed OpenSSL vulnerability that allows unauthenticated attackers to cause memory-exhaustion denial-of-service by sending a specially crafted 11-byte TLS handshake packet that triggers an unbounded allocation; the report details impact, exploitation mechanics, mitigation strategies (rate limiting, timeouts, WAF/proxy) and remediation guidance to update OpenSSL when patches are released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.