OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

2026-07-20T13:24:04Z053f4cbace72c1f334d6d97018b521ecdbd3e8b9c1e4aee481aedc32814f6b00
buffer-allocationdenial-of-servicehollowbytememory-exhaustionmemory-leakopensslpatchsecurity-advisorysecurityweek

What happened

SecurityWeek reports that OpenSSL developers quietly fixed a denial-of-service issue dubbed “HollowByte” where specially crafted payloads trigger buffer pre-allocations that are not freed, allowing attackers to exhaust server memory. The fix has been applied upstream; operators should verify OpenSSL versions, apply the patched release, and monitor for abnormal memory consumption or repeated malformed connection payloads. Mitigations include upgrading to the patched OpenSSL, applying WAF/rate-limiting to limit malformed traffic, and reviewing logs/telemetry for signs of memory-exhaustion DoS.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
053f4cbace72c1f334d6d97018b521ecdbd3e8b9c1e4aee481aedc32814f6b00
Enrichment time
2026-07-20T13:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.