VDB
Sign up
MEDIUM5.5

PYSEC-2026-925

sosreport Exposure of Sensitive Information vulnerability

Quick fix

PYSEC-2026-925 — sosreport: upgrade to the fixed version with the command below.

pip install --upgrade 'sosreport>=4.4'

Details

It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/sosreport
Introduced in: 0Fixed in: 4.4
Fixpip install --upgrade 'sosreport>=4.4'

References