devpi-server, Information Disclosure, CVE-2026-54723 (Critical) -DC-Aug2026-1640

Listen to this Post

CVE-2026-54723 is a critical information disclosure vulnerability identified in devpi-server. The core of the issue lies in the replication protocol. When a devpi-server instance is configured with the `primary` (or the deprecated master) role, the `+changelog` URL route becomes accessible. This route is intended for replication purposes, but due to a logic error, it can be exploited to read the entire database content.
An attacker can use a trivially modified GET request to the `+changelog` endpoint to exfiltrate sensitive data. This includes password hashes, as well as the IDs and salts of tokens from the `devpi-tokens` plugin. While the leaked hashes use the robust `argon2` algorithm, making them resistant to brute-force attacks, they are still susceptible to dictionary attacks. Furthermore, if `devpi-tokens` are in use and are public, an attacker might be able to derive the server secret, leading to a complete compromise of the token system. Beyond the data leak, this vulnerability can be weaponized to cause a denial of service by consuming significant CPU, IO, and bandwidth, depending on the database size. The vulnerability is fixed in versions 6.20.2 and 7.0.0b3.

DailyCVE Form

Platform: devpi-server
Version: < 6.20.2
Vulnerability: Info Disclosure
Severity: Critical
Date: 2026-06-11

Prediction: 2026-06-11

What Undercode Say:

Analytics

To check if your devpi-server instance is vulnerable, you can query the server’s version and check its configuration. The following bash command can be used to identify the server version:

curl -s http://<your-devpi-server>:<port> | grep "X-DEVPI-SERVER-VERSION"

To check if the replication protocol is enabled, look for the `–role` parameter in the server’s startup command or configuration. A vulnerable setup will have `–role=primary` or --role=master.

ps aux | grep devpi-server | grep role

Exploit: (Educational Purposes!)

The core of the exploit involves sending a modified GET request to the `+changelog` endpoint. An attacker can use `curl` to perform this action:

curl -X GET "http://<vulnerable-devpi-server>:<port>/+changelog" -H "Accept: application/json"

This request, when sent to a vulnerable server, will return the full database content, including sensitive information like password hashes and token data.

Protection

To protect against CVE-2026-54723, the following measures are recommended:
1. Upgrade: Immediately upgrade to a patched version, either `devpi-server 6.20.2` or devpi-server 7.0.0b3.
2. Change Role: If the replication protocol is not required, change the server’s role to standalone. This can be done by setting the `–role=standalone` parameter when starting the server.
3. Workaround: If the server is exclusively served through `nginx` with the `devpi-lockdown` plugin, the exploit is not known to be feasible.

Impact

The successful exploitation of this vulnerability has several severe impacts:
– Complete Database Leak: An attacker can read the entire database, including password hashes and authentication token secrets.
– Credential Compromise: While hashes are secure against brute-force, they are vulnerable to dictionary attacks. If a leak is suspected, all passwords must be changed.
– Server Secret Compromise: If tokens are public, the server secret can be derived, allowing for the forgery of authentication tokens.
– Denial of Service: The attack can be used to cause excessive CPU, IO, and bandwidth usage, potentially taking the server offline.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top