UNKNOWN PyPI

openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers

GHSA-2vhw-q7vh-7xv2 · CVE-2026-74879 · PYSEC-2026-3758

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Summary

The /ready endpoint in openssl_encrypt_server/server.py at lines 159-175 catches database errors and returns the full exception string in the response.

Affected Code

except Exception as e:
    return {"status": "not_ready", "reason": str(e)}

Impact

Database exception messages can leak:

  • Database hostnames and IP addresses
  • Connection parameters and port numbers
  • Driver version information
  • Potentially database credentials if included in connection string errors

This information is available to unauthenticated callers.

Recommended Fix

  • Return a generic error message: {"status": "not_ready", "reason": "database unavailable"}
  • Log the full exception server-side for debugging

Fix

Fixed in commit 7aa8787 on branch releases/1.4.x — replaced str(e) with generic "database check failed" message; full exception logged server-side at WARNING level.

Ready to move

Start Securing

Free, no credit card | First findings in minutes