CVE-2026-54723
devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +changelog route because verify_primary does not reject a missing identity and therefore fails to require ReplicaIdentity. The response can disclose complete database content, including Argon2 password hashes and identifiers and salts for devpi-tokens; exposed hashes may be subject to dictionary attacks, and public tokens may assist attempts to derive the server secret. Large responses can also consume significant CPU, input/output capacity, and bandwidth. Servers using the standalone role are not exposed through replication, and an instance served exclusively through nginx with devpi-lockdown redirects the request to login with no known exploit. This issue is fixed in devpi-server versions 6.20.2 and 7.0.0b3.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- EPSS probability
- 0.32%
- CWE
- CWE-304
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- devpi devpi
- devpi devpi
Weakness type
Related vulnerabilities
- CVE-2022-2302 — LENZE: Missing password verification in authorisation procedure
- CVE-2024-8954 — Authentication Bypass in composiohq/composio
- CVE-2022-2821 — Missing Critical Step in Authentication in namelessmc/nameless
- CVE-2024-45764 — Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. A
- CVE-2024-12048 — IDOR Vulnerability in transformeroptimus/superagi
- CVE-2019-16766 — 2FA bypass in Wagtail through new device path
- CVE-2026-55957 — Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
- CVE-2024-2172 — Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation