OpenSSL HollowByte Flaw Lets Attackers Freeze Server Memory
Eleven-byte TLS requests can lock up hundreds of megabytes on OpenSSL servers, exposing a silent DoS risk that OpenSSL failed to CVE‑tag. Learn the details and mitigation steps.
Eleven-byte TLS requests can lock up hundreds of megabytes on OpenSSL servers, exposing a silent DoS risk that OpenSSL failed to CVE‑tag. Learn the details and mitigation steps.
HollowByte lets attackers trigger OpenSSL memory exhaustion with an 11‑byte payload, bloating servers until a restart. Fixed in OpenSSL 4.0.1, it hits NGINX and Apache.
A severe vulnerability in Apache HTTP/2 protocol handling allows for denial-of-service (DoS) and potential remote code execution (RCE).
Cisco patched a Crosswork Network Controller denial-of-service vulnerability that requires manual rebooting for recovery.