
Okta Discloses HollowByte DoS Vulnerability in OpenSSL Leading to Memory Exhaustion
Breaking NewsHackingDoSHollowByteinformation securityIT securityOpenSSLSecurity News
Okta’s Red Team disclosed a denial-of-service (DoS) vulnerability in OpenSSL named HollowByte, which allows remote, unauthenticated attackers to exhaust server memory. The flaw is triggered by an 11-byte payload that forces the server to allocate up to 131 KB of memory. The vulnerability was identified and reported by Okta, though no CVE ID or specific affected OpenSSL versions were mentioned. Exploitation could lead to memory exhaustion and subsequent DoS conditions on targeted systems. No patch release date or mitigation details were provided in the report.