---
id: CVE-2026-74879
aliases:
  - GHSA-2vhw-q7vh-7xv2
title: >-
  openssl-encrypt's readiness endpoint leaks database error details to
  unauthenticated callers
summary: >-
  openssl-encrypt's readiness endpoint leaks database error details to
  unauthenticated callers
severity: medium
vendor: openssl-encrypt
product: openssl-encrypt
ecosystem: pip
affected:
  - openssl-encrypt < 1.4.0
patched:
  - openssl-encrypt 1.4.0
published: '2026-04-01'
updated: '2026-08-18'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-2vhw-q7vh-7xv2'
references:
  - url: >-
      https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-2vhw-q7vh-7xv2
  - url: >-
      https://github.com/jahlives/openssl_encrypt/commit/7aa8787f4de2e9a23f58fca067bb16c4c69d28bb
  - url: 'https://github.com/jahlives/openssl_encrypt'
tags:
  - osv
  - pip
ingestedAt: '2026-08-18T12:28:08.023Z'
epss: 0.00444
epssPercentile: 0.35908
---

## Overview

### Summary

The `/ready` endpoint in `openssl_encrypt_server/server.py` at **lines 159-175** catches database errors and returns the full exception string in the response.

### Affected Code

```python
except Exception as e:
    return {"status": "not_ready", "reason": str(e)}
```

### Impact

Database exception messages can leak:
- Database hostnames and IP addresses
- Connection parameters and port numbers
- Driver version information
- Potentially database credentials if included in connection string errors

This information is available to unauthenticated callers.

### Recommended Fix

- Return a generic error message: `{"status": "not_ready", "reason": "database unavailable"}`
- Log the full exception server-side for debugging

### Fix

Fixed in commit `7aa8787` on branch `releases/1.4.x` — replaced str(e) with generic "database check failed" message; full exception logged server-side at WARNING level.

## Affected packages

- `openssl-encrypt < 1.4.0`

## Remediation

Upgrade to a patched release:

- `openssl-encrypt 1.4.0`
