OpenSSL HollowByte: 11-Byte TLS Payload Causes Server Memory Exhaustion
A denial-of-service vulnerability in OpenSSL, named HollowByte by Okta’s Red Team, enables a remote unauthenticated attacker to permanently exhaust server memory using a crafted 11-byte TLS handshake payload. The flaw was quietly fixed in a multi-branch OpenSSL release on June 9, 2026. No official CVE advisory was published by the OpenSSL project at the time […]
OpenSSL HollowByte: 11-Byte TLS Payload Causes Server Memory Exhaustion Read Post »