Just discovered there is a huge information leak in the Response Header: Server: Werkzeug/0.0.1 Python/3.1.7 Please add option to drop this, or maybe to modify it. Something like @app.after_request def add_header(response): response.headers['Server'] = 'dummy' return response