// Alert

Okta threat report

// OktaMEDIUM

Okta Red Team disclosed HollowByte, a denial-of-service vulnerability in OpenSSL triggered by 11-byte malicious TLS handshake headers. The flaw causes memory exhaustion and heap fragmentation on glibc systems; unpatched servers can have significant RAM locked up by a single attacker. OpenSSL patched the issue in June 2026 releases without assigning a CVE or formal advisory, complicating discovery and deployment tracking.

// Get alerts for Okta