securityonline.info 7/20/2026, 1:58:27 AM · external

OpenSSL HollowByte flaw lets 11 byte attacks crash NGINX, Apache

OpenSSL HollowByte flaw lets 11 byte attacks crash NGINX, Apache
Developing story vulnerability 3 articles tracked
OpenSSL HollowByte denial-of-service vulnerability disclosed
CyberSIXT Evidence Panel
Primary Source sec.okta.com

THE OpenSSL HollowByte vulnerability, discovered by the Okta Red Team, allows remote attackers to crash web servers with a minimal payload of just eleven bytes, leading to out-of-memory conditions. This flaw affects crucial server software like NGINX and Apache. The attack exploits the memory management of OpenSSL during the initial secure connection, creating memory fragmentation until the server crashes. While patched versions exist (4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21), unpatched systems remain vulnerable. Security teams should urgently update their software to prevent potential disruptions.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline