logo

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

ID: 38cb4e72-67f9-555b-93c6-61631316ad6f

STIX ID: report--38cb4e72-67f9-555b-93c6-61631316ad6f

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

The report details HollowByte, a DoS flaw in OpenSSL that lets unauthenticated attackers trigger persistent server memory bloat by sending an 11‑byte TLS handshake fragment with a forged length header; OpenSSL has patched the issue in 4.0.1 and backported fixes to several 3.x releases, and organizations are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.