MEDIUM 6.5 GitHub

CVE-2026-54723

devpi-server may leak database contents

### Impact If the replication protocol is enabled by using the ``primary`` (or deprecated ``master``) role for a server instance, then the ``+changelog`` URL route can be used to read the complete database content including password hashes, and the ids and salts of tokens from ``devpi-tokens`` by using a trivially modified GET request. The leaked hashes use the ``argon2`` algorithm, so they are not immediately at risk by brute-force methods, but dictionary attacks are feasible. If a database l

Affected Products

References

Published: 2026-08-18 · Source: GitHub · Feed updated: 2026-08-19
This medium severity vulnerability with a CVSS score of 6.5 was published on 2026-08-18 via GitHub. Affected: pip/devpi-server < 6.20.2.
vulnfeed aggregates 11955 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.