Which 2014 OpenSSL vulnerability allowed attackers to read data from a server's memory?

The story behind the answer

Heartbleed was the 2014 OpenSSL vulnerability that allowed attackers to read data from a server’s memory.

The flaw affected the Heartbeat extension in certain versions of OpenSSL, an open-source implementation used to help secure internet communications. Because the extension failed to properly check the length of a requested message, a remote attacker could request more data than had actually been supplied and receive leftover memory contents.

That memory could contain usernames, passwords, cookies, private keys, or other sensitive information, although the exact data depended on what the server had recently handled. Heartbleed was publicly disclosed on 7 April 2014 and identified as CVE-2014-0160.

Heartbleed was not a failure of the TLS encryption mathematics itself. It was an implementation bug in software used with TLS. Administrators had to update OpenSSL, replace potentially exposed private keys, and invalidate affected credentials.

Source: Wikipedia · fact-checked Sept. 2026

Add question to a list

Choose a list to keep this question in: