On the "HollowByte" denial-of-service report
Blog on OpenSSL Library <[email protected]> Thu, 23 Jul 2026 01:00:22 -0000
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <9b7d0cf1-6d35-49ff-81c2-09786d43195f@localhost> |
Over the past week a denial-of-service (DoS) report against OpenSSL, named "HollowByte" by the [Okta Red Team](https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding- in-11-bytes/) who reported it, has received a good deal of press attention. A number of the articles ask reasonable questions about how we assessed the report and why we handled the fix the way we did. This post sets out our analysis and the reasoning behind our decisions. We are grateful to the Okta Red Team for the report and for the detail they put into it. The behaviour they describe is real, and we have changed OpenSSL in response to it. But the report combines two quite different things under a single headline, and separating them is the key to understanding our response. URL: https://openssl-library.org/post/2026-07-21-hollowbyte/ -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/9b7d0cf1-6d35-49ff-81c2-09786d43195f%40localhost.