THREAT OPS › Threat News › [GHSA] GHSA-m5pq-69xg-vcq3 (medium) — devpi-server may leak database contents
[GHSA] GHSA-m5pq-69xg-vcq3 (medium) — devpi-server may leak database contents
GHSA-m5pq-69xg-vcq3 Severity: medium CVE: CVE-2026-54723
devpi-server may leak database contents
### Impact
If the replication protocol is enabled by using the ``primary`` (or deprecated ``master``) role for a server instance, then the ``+changelog`` URL route can be used to read the complete database content including password hashes, and the ids and salts of tokens from ``devpi-tokens`` by us
Indicators of compromise
- CVE-2026-54723cve
Original source: https://github.com/advisories/GHSA-m5pq-69xg-vcq3