MEDIUM 6.5 GitHub
CVE-2026-54723
devpi-server may leak database contents
### Impact
If the replication protocol is enabled by using the ``primary`` (or deprecated ``master``) role for a server instance, then the ``+changelog`` URL route can be used to read the complete database content including password hashes, and the ids and salts of tokens from ``devpi-tokens`` by using a trivially modified GET request.
The leaked hashes use the ``argon2`` algorithm, so they are not immediately at risk by brute-force methods, but dictionary attacks are feasible. If a database l
Affected Products
- pip/devpi-server < 6.20.2
References
- https://github.com/advisories/GHSA-m5pq-69xg-vcq3
- https://github.com/devpi/devpi/security/advisories/GHSA-m5pq-69xg-vcq3
- https://github.com/advisories/GHSA-m5pq-69xg-vcq3
This medium severity vulnerability with a CVSS score of 6.5 was published on 2026-08-18 via GitHub. Affected: pip/devpi-server < 6.20.2.
vulnfeed aggregates 11955 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.