Skip to content

fix(security): replace raw exception string in HTTP 500 response (VULN-115235) - #250

Merged
etserend merged 1 commit into
mainfrom
fix/vuln-115235-stack-trace-disclosure
Oct 2, 2026
Merged

etserend merged 1 commit into
mainfrom
fix/vuln-115235-stack-trace-disclosure

Conversation

@etserend

Copy link
Copy Markdown
Contributor

Replace str(e) in the generate_startup() 500 handler with a generic message so internal exception details are not disclosed to HTTP callers.

Fixes VULN-115235 (SAST: flask-information-disclosure, OWASP A6).

…N-115235)

Return a generic error message instead of str(e) to prevent internal
exception details from being disclosed to HTTP callers.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@etserend
etserend requested a review from pradystar September 17, 2026 17:18
@etserend
etserend merged commit 6058a84 into main Oct 2, 2026
13 checks passed
@etserend
etserend deleted the fix/vuln-115235-stack-trace-disclosure branch October 2, 2026 17:18
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 2, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants