๐Ÿ” CVE Alert

CVE-2026-54723

MEDIUM 6.5

devpi: Database contents leak

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +changelog route because verify_primary does not reject a missing identity and therefore fails to require ReplicaIdentity. The response can disclose complete database content, including Argon2 password hashes and identifiers and salts for devpi-tokens; exposed hashes may be subject to dictionary attacks, and public tokens may assist attempts to derive the server secret. Large responses can also consume significant CPU, input/output capacity, and bandwidth. Servers using the standalone role are not exposed through replication, and an instance served exclusively through nginx with devpi-lockdown redirects the request to login with no known exploit. This issue is fixed in devpi-server versions 6.20.2 and 7.0.0b3.

CWE CWE-304
Vendor devpi
Product devpi
Published Sep 14, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for devpi devpi

Be the first to know when new medium vulnerabilities affecting devpi devpi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
Low

Affected Versions

devpi / devpi
< 6.20.2 >= 7.0.0b1, < 7.0.0b3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/devpi/devpi/security/advisories/GHSA-m5pq-69xg-vcq3 github.com: https://github.com/devpi/devpi/commit/b4ea49fed4a6233d63f8509c3bf7efafc9b2db17 github.com: https://github.com/devpi/devpi/releases/tag/server-6.20.2