OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

A newly discovered vulnerability in OpenSSL, a widely-used cryptographic library, has the potential to freeze server memory with carefully crafted TLS requests. The issue, dubbed “HollowByte,” affects systems using OpenSSL 3.x and can be exploited by attackers sending 11-byte TLS messages. This flaw poses a significant threat to organizations that rely on secure online transactions, as it could allow hackers to disrupt services or steal sensitive information.

The HollowByte vulnerability stems from an error in how OpenSSL handles TLS (Transport Layer Security) messages. When a client sends an excessively long message, the library’s internal buffer can become overwhelmed, leading to memory exhaustion and ultimately causing the server to freeze. Attackers can exploit this flaw by crafting 11-byte TLS requests that are specifically designed to trigger the issue.

This vulnerability affects systems using OpenSSL 3.x, which is widely used in production environments due to its performance and security features. Organizations relying on secure online transactions, including e-commerce websites, banks, and other financial institutions, are particularly vulnerable to this issue. If exploited, the HollowByte flaw could allow attackers to freeze server memory, disrupt services, or even steal sensitive information.

The discovery of the HollowByte vulnerability highlights the importance of using AI-powered tools in cybersecurity. Researchers used an AI-driven approach to identify the error, demonstrating the effectiveness of machine learning models in detecting complex vulnerabilities. This development underscores the growing role of AI in identifying and mitigating security threats.

To mitigate the risk of the HollowByte flaw, organizations should update their OpenSSL versions to the latest patch release as soon as possible. Additionally, users can implement workarounds such as limiting TLS message lengths or using alternative cryptographic libraries that are not affected by this issue. As the cybersecurity landscape continues to evolve, it is essential for organizations to stay vigilant and adapt to emerging threats.

By taking proactive steps to address vulnerabilities like HollowByte, organizations can reduce their exposure to potential attacks and maintain the integrity of their online services.


Source: The Hacker News — 2026-07-17