On the "HollowByte" denial-of-service report

Blog on OpenSSL Library <[email protected]> Thu, 23 Jul 2026 01:00:22 -0000
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <9b7d0cf1-6d35-49ff-81c2-09786d43195f@localhost>
Over the past week a denial-of-service (DoS) report against OpenSSL, named
"HollowByte" by the [Okta Red
Team](https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-
in-11-bytes/) who reported it, has received a good deal of press attention. A
number of the articles ask reasonable questions about how we assessed the
report and why we handled the fix the way we did. This post sets out our
analysis and the reasoning behind our decisions.

We are grateful to the Okta Red Team for the report and for the detail they
put into it. The behaviour they describe is real, and we have changed OpenSSL
in response to it. But the report combines two quite different things under a
single headline, and separating them is the key to understanding our response.



URL: https://openssl-library.org/post/2026-07-21-hollowbyte/

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/9b7d0cf1-6d35-49ff-81c2-09786d43195f%40localhost.