Over the past week a denial-of-service (DoS) report against OpenSSL, named
"HollowByte" by the [Okta Red
Team](
https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-
in-11-bytes/) who reported it, has received a good deal of press attention. A
number of the articles ask reasonable questions about how we assessed the
report and why we handled the fix the way we did. This post sets out our
analysis and the reasoning behind our decisions.
We are grateful to the Okta Red Team for the report and for the detail they
put into it. The behaviour they describe is real, and we have changed OpenSSL
in response to it. But the report combines two quite different things under a
single headline, and separating them is the key to understanding our response.
URL:
https://openssl-library.org/post/2026-07-21-hollowbyte/