THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-m5pq-69xg-vcq3 (medium) — devpi-server may leak database contents

[GHSA] GHSA-m5pq-69xg-vcq3 (medium) — devpi-server may leak database contents

medgithub_advisoriesPublished 2026-08-18

GHSA-m5pq-69xg-vcq3 Severity: medium CVE: CVE-2026-54723

devpi-server may leak database contents

### Impact

If the replication protocol is enabled by using the ``primary`` (or deprecated ``master``) role for a server instance, then the ``+changelog`` URL route can be used to read the complete database content including password hashes, and the ids and salts of tokens from ``devpi-tokens`` by us

Indicators of compromise

Original source: https://github.com/advisories/GHSA-m5pq-69xg-vcq3