OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
2026-07-20T13:24:04Z•053f4cbace72c1f334d6d97018b521ecdbd3e8b9c1e4aee481aedc32814f6b00
buffer-allocationdenial-of-servicehollowbytememory-exhaustionmemory-leakopensslpatchsecurity-advisorysecurityweek
What happened
SecurityWeek reports that OpenSSL developers quietly fixed a denial-of-service issue dubbed “HollowByte” where specially crafted payloads trigger buffer pre-allocations that are not freed, allowing attackers to exhaust server memory. The fix has been applied upstream; operators should verify OpenSSL versions, apply the patched release, and monitor for abnormal memory consumption or repeated malformed connection payloads. Mitigations include upgrading to the patched OpenSSL, applying WAF/rate-limiting to limit malformed traffic, and reviewing logs/telemetry for signs of memory-exhaustion DoS.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 053f4cbace72c1f334d6d97018b521ecdbd3e8b9c1e4aee481aedc32814f6b00
- Enrichment time
- 2026-07-20T13:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.