OpenSSL Patches HollowByte Flaw That Can Crash Servers With 11 Bytes
OpenSSL underpins encrypted communications across servers, applications and network appliances, giving flaws in the open-source library potentially broad supply-chain reach. Okta’s Red Team named the memory-exhaustion bug HollowByte after finding that an unauthenticated attacker could send an incomplete 11-byte TLS message, prompting a vulnerable server to allocate memory based on an unverified length field and wait for data that never arrives.
Okta disclosed HollowByte on July 16, 2026, saying each malicious connection could reserve as much as 131 KB. In a test involving a 1-GB NGINX server, memory fragmentation stranded 547 MB and the process was eventually terminated for running out of memory. OpenSSL issued version 4.0.1 on June 9 and backported the fix to 3.6.3, 3.5.7, 3.4.6 and 3.0.21. The issue has not been assigned a CVE identifier.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.