Description
Debug modes in frameworks such as Django, Flask and FastAPI provide detailed errors during development. In production, they may include stack traces, source excerpts, local variables or configuration values in responses.
Flask's TESTING setting is separate from debug mode. It enables testing behavior in extensions and implicitly enables exception propagation unless PROPAGATE_EXCEPTIONS is set separately. TESTING=True does not itself turn on Flask's interactive debugger, but it can change normal production error handling and let testing behavior affect real requests.
Potential impact
- Internal information exposure: Django's detailed error pages and FastAPI's debug tracebacks may disclose source locations, settings and request-processing details.
- Remote code execution: An exposed Flask/Werkzeug interactive debugger can execute Python code from a browser. Its PIN must not be treated as a security control.
- Changed error and extension behavior: Flask testing mode may propagate exceptions instead of passing them to application error handlers, and extensions may enable test-specific behavior.
Remediation
- Keep Django
DEBUG, FlaskDEBUGandTESTING, and FastAPIdebugset to the booleanFalsein production. - Separate development, testing and production configuration, and automatically verify the effective settings before deployment.
- Use a production server instead of the framework's development server or interactive debugger. Configure generic error responses, server-side logging and alerts.
- Do not pass environment variable strings directly to boolean arguments.
os.getenv("DEBUG", "False")returns a string, and the nonempty string"False"is truthy in Python. Parse environment settings into booleans in a typed configuration layer first.
Keep settings needed for development or testing separate from production, and check the final values used by the deployment.
Examples
Django
Before
# settings/production.py
DEBUG = True
After
# settings/production.py
DEBUG = False
Flask debug mode
Before
from flask import Flask
app = Flask(__name__)
app.run(debug=True)
After
from flask import Flask
app = Flask(__name__)
app.config["DEBUG"] = False
# Run with a production WSGI server, not the Flask development server.
Flask testing mode
Before
from flask import Flask
app = Flask(__name__)
app.config.update(TESTING=True)
# app.testing = True enables the same setting.
After
from flask import Flask
app = Flask(__name__)
app.config.update(TESTING=False)
FastAPI
Before
from fastapi import FastAPI
app = FastAPI(debug=True)
After
from fastapi import FastAPI
app = FastAPI(debug=False)
Explanation:
- Before: Enables detailed errors or test-specific behavior in production.
- After: Disables these features with the actual boolean
Falsein production configuration.
References
- Flask 3.1.x: Configuration Handling —
TESTING - Flask 3.1.x: Debugging Application Errors
- Django 5.2 LTS: Deployment checklist —
DEBUG - FastAPI:
FastAPIclass —debug - OWASP: A02:2025 Security Misconfiguration
- OWASP: A05:2021 Security Misconfiguration
- CWE: CWE-489: Active Debug Code