Junglewise Threat Intelligence

CVE-2026-74879: PYSEC-2026-3758 - openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exce

CVE-2026-74879 · Severity: medium · CVSS 4 · Published 2026-08-17

Technologies: openssl-encrypt (PyPI), Openssl-Encrypt Openssl Encrypt. Vendors: PyPI.

Executive brief

openssl-encrypt is a Python library for encryption operations. Its readiness health check endpoint (/ready) exposes sensitive database error details—including hostnames, connection parameters, and potentially credentials—to anyone on the network without authentication. An attacker can probe this endpoint to gather infrastructure information useful for further attacks.

Technical details

The vulnerability is an information disclosure flaw (CWE-201) in the /ready endpoint handler (openssl_encrypt_server/server.py, lines 159-175). When a database error occurs, the endpoint catches the exception and returns the full exception string in the JSON response to callers without authentication. This can expose database hostnames, IP addresses, port numbers, driver versions, and potentially credentials embedded in connection string errors. The attack vector is network-based with no authentication or user interaction required. The fix, deployed in commit 7aa8787, replaces the exception string with a generic "database check failed" message while logging the full exception server-side for debugging.

Affected products

  • openssl-encrypt openssl-encrypt all versions before 1.4.0

Timeline

  • 2026-04-01: disclosed
  • 2026-04-01: patched: Fixed in commit 7aa8787 on releases/1.4.x branch

References

Related threats