Executive brief
openssl-encrypt is a Python library for encryption operations. Its readiness health check endpoint (/ready) exposes sensitive database error details—including hostnames, connection parameters, and potentially credentials—to anyone on the network without authentication. An attacker can probe this endpoint to gather infrastructure information useful for further attacks.
Technical details
The vulnerability is an information disclosure flaw (CWE-201) in the /ready endpoint handler (openssl_encrypt_server/server.py, lines 159-175). When a database error occurs, the endpoint catches the exception and returns the full exception string in the JSON response to callers without authentication. This can expose database hostnames, IP addresses, port numbers, driver versions, and potentially credentials embedded in connection string errors. The attack vector is network-based with no authentication or user interaction required. The fix, deployed in commit 7aa8787, replaces the exception string with a generic "database check failed" message while logging the full exception server-side for debugging.
Affected products
- openssl-encrypt openssl-encrypt all versions before 1.4.0
Timeline
- 2026-04-01: disclosed
- 2026-04-01: patched: Fixed in commit 7aa8787 on releases/1.4.x branch