
HollowByte DoS Vulnerability Discovered in Unpatched OpenSSL Servers
CybersecurityVulnerabilitiesDenial-of-ServiceSoftwarePatches
A denial-of-service (DoS) vulnerability named 'HollowByte' was identified in unpatched OpenSSL servers, allowing an attacker to allocate up to 131 KB of memory per process with an 11-byte TLS request. The flaw, reported by Okta's Red Team, causes memory exhaustion until the affected process restarts, particularly on glibc-based systems. OpenSSL released a fix in June 2026 without assigning a CVE, issuing an advisory, or documenting the change in the changelog. No remote code execution or authentication requirements were mentioned, but the impact is limited to service disruption. The vulnerability was addressed silently in the patch.