id: PYSEC-2026-135 published: "2026-04-09T16:16:23.890Z" modified: "2026-04-17T20:17:02.457Z" aliases: - CVE-2025-14551 details: In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the attached logs. affected: - package: name: subiquity ecosystem: PyPI purl: pkg:pypi/subiquity ranges: - type: ECOSYSTEM events: - introduced: "0" - last_affected: 24.04.4 ecosystem_specific: {} references: - type: FIX url: https://github.com/canonical/subiquity/pull/2357 - type: FIX url: https://github.com/canonical/subiquity/pull/2358 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H