What is Heartbleed? In short, Heartbleed is a security vulnerability where an attacker can use a TLS heartbeat packet to reveal up to 64k of memory from the server's buffer; this information can include anything that would be stored in that section of memory including unencrypted usernames and passwords.