On the "HollowByte" denial-of-service report

9 views
Skip to first unread message

Blog on OpenSSL Library

unread,
Jul 22, 2026, 9:00:38 PMJul 22
to openss...@openssl.org
Over the past week a denial-of-service (DoS) report against OpenSSL, named
"HollowByte" by the [Okta Red
Team](https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-
in-11-bytes/) who reported it, has received a good deal of press attention. A
number of the articles ask reasonable questions about how we assessed the
report and why we handled the fix the way we did. This post sets out our
analysis and the reasoning behind our decisions.

We are grateful to the Okta Red Team for the report and for the detail they
put into it. The behaviour they describe is real, and we have changed OpenSSL
in response to it. But the report combines two quite different things under a
single headline, and separating them is the key to understanding our response.



URL: https://openssl-library.org/post/2026-07-21-hollowbyte/
Reply all
Reply to author
Forward
0 new messages