Skip to content
HollowByte flaw allows unauthenticated OpenSSL memory exhaustion

HollowByte flaw allows unauthenticated OpenSSL memory exhaustion

Feeds.4Sysops IT News July 17, 2026

A newly discovered vulnerability named HollowByte allows unauthenticated attackers to trigger a denial-of-service condition on OpenSSL servers using a payload of only 11 bytes. The flaw stems from how the library handles TLS handshake headers, which contain a field declaring the size of the incoming message body. Vulnerable versions trust this header and allocate the requested memory immediately before the actual data arrives or is validated. Source

Extracted Entities

Attack Types (1)

Tools (1)

Vulnerabilities (1)