Mark RadarMARK RADAR
EN
Event File AI Claude

OpenSSL Patches HollowByte Flaw That Can Crash Servers With 11 Bytes

1 reports · First detected 2026-07-20 · Last active 2026-07-20

OpenSSL underpins encrypted communications across servers, applications and network appliances, giving flaws in the open-source library potentially broad supply-chain reach. Okta’s Red Team named the memory-exhaustion bug HollowByte after finding that an unauthenticated attacker could send an incomplete 11-byte TLS message, prompting a vulnerable server to allocate memory based on an unverified length field and wait for data that never arrives.

Okta disclosed HollowByte on July 16, 2026, saying each malicious connection could reserve as much as 131 KB. In a test involving a 1-GB NGINX server, memory fragmentation stranded 547 MB and the process was eventually terminated for running out of memory. OpenSSL issued version 4.0.1 on June 9 and backported the fix to 3.6.3, 3.5.7, 3.4.6 and 3.0.21. The issue has not been assigned a CVE identifier.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR