Security researchers at Okta Security have uncovered a denial-of-service vulnerability in OpenSSL that allows attackers to overload the memory of web servers and other systems without prior authentication.
The Hollowbyte vulnerability was patched in OpenSSL version 4.0, released on June 9. 1. As a result, OpenSSL no longer trusts the information in the header and instead only increases the receive buffer as needed once the expected data arrives. According to the researchers, the fix has also been backported to OpenSSL versions 3.6.3, 3.5.7, 3.4.6, and 3.0.21.
Resolved Defects May 2026 Patch 2
SHEND-3337
Update OpenSSL
All ODBC drivers (with the exception of Mysql) have been updated to OpenSSL 3.0.20 or greater.