CVE-2026-54723
CVE-2026-54723 is a medium-severity vulnerability with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-304.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- EPSS exploit prediction: 0% (36th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-304
- Published:
- Last modified:
Description
devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +changelog route because verify_primary does not reject a missing identity and therefore fails to require ReplicaIdentity. The response can disclose complete database content, including Argon2 password hashes and identifiers and salts for devpi-tokens; exposed hashes may be subject to dictionary attacks, and public tokens may assist attempts to derive the server secret. Large responses can also consume significant CPU, input/output capacity, and bandwidth. Servers using the standalone role are not exposed through replication, and an instance served exclusively through nginx with devpi-lockdown redirects the request to login with no known exploit. This issue is fixed in devpi-server versions 6.20.2 and 7.0.0b3.
Frequently asked questions
- What is CVE-2026-54723?
- devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +changelog route because verify_primary does not reject a missing identity and therefore fails to require ReplicaIdentity. The response can disclose complete database content, including Argon2 password hashes and identifiers and salts for devpi-tokens; exposed hashes may be subject to dictionary attacks, and public tokens may assist attempts to derive the server secret. Large responses can also consume significant CPU, input/output capacity, and bandwidth. Servers using the standalone role are not exposed through replication, and an instance served exclusively through nginx with devpi-lockdown redirects the request to login with no known exploit. This issue is fixed in devpi-server versions 6.20.2 and 7.0.0b3.
- How severe is CVE-2026-54723?
- CVE-2026-54723 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability low.
- Is CVE-2026-54723 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (36th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-54723?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-54723 published?
- CVE-2026-54723 was published on 2026-09-14 and last updated on 2026-09-30.
References
- https://github.com/devpi/devpi/commit/b4ea49fed4a6233d63f8509c3bf7efafc9b2db17
- https://github.com/devpi/devpi/releases/tag/server-6.20.2
- https://github.com/devpi/devpi/security/advisories/GHSA-m5pq-69xg-vcq3
Other CWE-304 vulnerabilities
- CVE-2023-54391 — Critical (CVSS 9.8): Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in…
- CVE-2024-8954 — Critical (CVSS 9.8): In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the…
- CVE-2024-2172 — Critical (CVSS 9.8): The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to…
- CVE-2026-94052 — Critical (CVSS 9.1): A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or…
- CVE-2026-59564 — Critical (CVSS 9.1): An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and…
- CVE-2026-61466 — Critical (CVSS 9.1): In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope`…