Stack trace exposure

Stack trace exposure

Description

Writing a runtime stack trace or panic dump directly to an HTTP response can expose internal package structure, file paths and runtime context.

Potential impact

  • Attackers may use internal structure information to refine further attacks.
  • Some runtime values or paths may reveal sensitive information.

Remediation

  • Write detailed stack traces only to protected server logs and remove sensitive values.
  • Return only generic error messages to users.
  • Restrict log access and retention.

Examples

Before

go
w.Write(debug.Stack())

After

go
log.Print(string(debug.Stack()))
http.Error(w, "internal server error", http.StatusInternalServerError)

Explanation:

  • Before: The HTTP response exposes stack traces or panic dumps, potentially revealing packages, paths, framework structure and sensitive runtime context.
  • After: Detailed traces go only to server logs, while the client receives a generic error message.

References