// OktaMEDIUM
Okta Red Team disclosed HollowByte, a denial-of-service vulnerability in OpenSSL triggered by 11-byte malicious TLS handshake headers. The flaw causes memory exhaustion and heap fragmentation on glibc systems; unpatched servers can have significant RAM locked up by a single attacker. OpenSSL patched the issue in June 2026 releases without assigning a CVE or formal advisory, complicating discovery and deployment tracking.
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Atta(opens in a new tab)
- OpenSSL 'HollowByte' Flaw Enables Memory Exhaustion DoS with Jus(opens in a new tab)
- This Week In Security: AI Is A Mess, Hacking Car Chargers, An Op(opens in a new tab)
// Get alerts for Okta