PYSEC-2026-1717
OMERO.web displays unecessary user information when requesting password reset
Quick fix
PYSEC-2026-1717 — omero-web: upgrade to the fixed version with the command below.
pip install --upgrade 'omero-web>=5.29.2'Details
### Background
If an error occurred when resetting a user's password using the ``Forgot Password`` option in OMERO.web, the error message displayed on the Web page can disclose information about the user.
### Impact OMERO.web before 5.29.1
### Patches User should upgrade to 5.29.2 or higher
### Workarounds Disable the ``Forgot password`` option in OMERO.web using the ``omero.web.show_forgot_password`` configuration property[^1].
Thanks to Christopher Youd who reported the issue.
Open an issue in [omero-web](https://github.com/ome/omero-web) Email us at [security@openmicroscopy.org](mailto:security@openmicroscopy.org)
[^1]: https://omero.readthedocs.io/en/stable/sysadmins/config.html#omero.web.show_forgot_password
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/ome/omero-web/security/advisories/GHSA-gpmg-4x4g-mr5r[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-54791[ADVISORY]
- https://github.com/ome/omero-web/commit/8aa2789e8f759c73f1517abe9a0abd44e86644ad[WEB]
- https://github.com/ome/omero-web[PACKAGE]
- https://pypi.org/project/omero-web[PACKAGE]
- https://github.com/advisories/GHSA-gpmg-4x4g-mr5r[ADVISORY]