Description
devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +changelog route because verify_primary does not reject a missing identity and therefore fails to require ReplicaIdentity. The response can disclose complete database content, including Argon2 password hashes and identifiers and salts for devpi-tokens; exposed hashes may be subject to dictionary attacks, and public tokens may assist attempts to derive the server secret. Large responses can also consume significant CPU, input/output capacity, and bandwidth. Servers using the standalone role are not exposed through replication, and an instance served exclusively through nginx with devpi-lockdown redirects the request to login with no known exploit. This issue is fixed in devpi-server versions 6.20.2 and 7.0.0b3.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Leakage via unauthenticated database exposure
Action: Immediate Patch
AI Analysis

Impact

devpi‑server in primary or deprecated master mode permits an unauthenticated, modified GET request to the +changelog endpoint because the verify_primary check does not reject a missing identity, thus failing to require ReplicaIdentity. Consequently, the server returns the entire database contents, exposing Argon2 password hashes, devpi‑token identifiers and salts. The exposed hashes can be subject to dictionary attacks, and public tokens may help attackers derive the server secret. Large responses can also consume significant CPU, I/O capacity, and bandwidth, potentially leading to a denial‑of‑service condition.

Affected Systems

The vulnerability affects instances of devpi Server version 6.x prior to 6.20.2 and 7.x before 7.0.0b3 that are running in the primary or the deprecated master configuration. Standalone mode servers are not affected by replication, and servers that are behind nginx and use devpi‑lockdown are currently not exploitable through this vector. The attack surface is limited to servers exposing the +changelog endpoint without proper authentication enforcement.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity. The EPSS score is less than 1%, signifying a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires only an unauthenticated HTTP GET request to a publicly accessible +changelog URL on a server configured as primary/master, which makes it straightforward to execute from anywhere on the network or the internet. Successful exploitation allows an attacker to read full database contents, harvest password hashes, and potentially use public tokens to aid further attacks or abuse. The lack of authentication coupled with the ability to return large payloads also raises the risk of a resource exhaustion denial‑of‑service condition.

Generated by OpenCVE AI on September 20, 2026 at 23:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade devpi‑server to version 6.20.2 or newer, or to 7.0.0b3 or later, which restores the ReplicaIdentity requirement and blocks unauthenticated access to +changelog.
  • If an upgrade cannot be performed immediately, configure the server to operate in standalone mode or apply devpi‑lockdown so that the +changelog route redirects unauthenticated requests to a login page.
  • Block or restrict HTTP GET traffic to the +changelog path at the firewall or reverse‑proxy level, ensuring that only authenticated requests reach the application.

Generated by OpenCVE AI on September 20, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-m5pq-69xg-vcq3 devpi-server may leak database contents
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Devpi
Devpi devpi
Vendors & Products Devpi
Devpi devpi

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +changelog route because verify_primary does not reject a missing identity and therefore fails to require ReplicaIdentity. The response can disclose complete database content, including Argon2 password hashes and identifiers and salts for devpi-tokens; exposed hashes may be subject to dictionary attacks, and public tokens may assist attempts to derive the server secret. Large responses can also consume significant CPU, input/output capacity, and bandwidth. Servers using the standalone role are not exposed through replication, and an instance served exclusively through nginx with devpi-lockdown redirects the request to login with no known exploit. This issue is fixed in devpi-server versions 6.20.2 and 7.0.0b3.
Title devpi: Database contents leak
Weaknesses CWE-304
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:21:50.993Z

Reserved: 2026-06-15T23:07:33.232Z

Link: CVE-2026-54723

cve-icon Vulnrichment

Updated: 2026-09-14T18:21:47.387Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:53.703

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-54723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:15:04Z

Weaknesses
  • CWE-304

    Missing Critical Step in Authentication