VDB
Sign up
MEDIUM5.3

PYSEC-2026-1717

OMERO.web displays unecessary user information when requesting password reset

Quick fix

PYSEC-2026-1717 — omero-web: upgrade to the fixed version with the command below.

pip install --upgrade 'omero-web>=5.29.2'

Details

### Background

If an error occurred when resetting a user's password using the ``Forgot Password`` option in OMERO.web, the error message displayed on the Web page can disclose information about the user.

### Impact OMERO.web before 5.29.1

### Patches User should upgrade to 5.29.2 or higher

### Workarounds Disable the ``Forgot password`` option in OMERO.web using the ``omero.web.show_forgot_password`` configuration property[^1].

Thanks to Christopher Youd who reported the issue.

Open an issue in [omero-web](https://github.com/ome/omero-web) Email us at [security@openmicroscopy.org](mailto:security@openmicroscopy.org)

[^1]: https://omero.readthedocs.io/en/stable/sysadmins/config.html#omero.web.show_forgot_password

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/omero-web
Introduced in: 0Fixed in: 5.29.2
Fixpip install --upgrade 'omero-web>=5.29.2'

References