devpi-server
devpi-server: backend for hosting private package indexes and PyPI on-demand mirrors
Activity
- Latest release
- 2mo ago
- Total releases
- 111
- Cadence
- ~39 days
- Last 12 months
- 11
Details
- License
- MIT
- First release
- Apr 30, 2013
| Version | Released | |
|---|---|---|
7.0.0b4
pre
|
7.0.0b4
pre
Dependencies (19)
+ 11 more |
|
6.20.3
patch
|
6.20.3
patch
Dependencies (20)
+ 12 more |
|
7.0.0b3
pre
|
7.0.0b3
pre
Dependencies (19)
+ 11 more |
|
6.20.2
patch
|
6.20.2
patch
Dependencies (20)
+ 12 more |
|
6.20.1
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.20.1
patch
Dependencies (20)
+ 12 more |
|
6.20.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.20.0
minor
Dependencies (20)
+ 12 more |
|
6.19.3
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.19.3
patch
Dependencies (20)
+ 12 more |
|
6.19.2
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.19.2
patch
Dependencies (20)
+ 12 more |
|
6.19.1
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.19.1
patch
Dependencies (19)
+ 11 more |
|
6.19.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.19.0
minor
Dependencies (18)
+ 10 more |
|
6.18.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.18.0
minor
Dependencies (18)
+ 10 more |
|
6.17.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.17.0
minor
Dependencies (17)
+ 9 more |
|
6.16.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.16.0
minor
Dependencies (17)
+ 9 more |
|
6.15.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.15.0
minor
Dependencies (17)
+ 9 more |
|
6.14.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.14.0
minor
Dependencies (17)
+ 9 more |
|
6.13.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.13.0
minor
Dependencies (17)
+ 9 more |
|
6.12.1
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.12.1
patch
Dependencies (17)
+ 9 more |
|
6.12.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.12.0
minor
Dependencies (16)
+ 8 more |
|
6.11.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.11.0
minor
Dependencies (16)
+ 8 more |
|
6.10.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.10.0
minor
Dependencies (16)
+ 8 more |
|
6.9.2
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.9.2
patch
Dependencies (16)
+ 8 more |
|
6.9.1
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.9.1
patch
Dependencies (16)
+ 8 more |
|
6.9.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.9.0
minor
Dependencies (16)
+ 8 more |
|
6.8.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.8.0
minor
Dependencies (16)
+ 8 more |
|
6.7.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.7.0
minor
Dependencies (16)
+ 8 more |
|
6.6.1
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.6.1
patch
Dependencies (16)
+ 8 more |
|
6.6.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.6.0
minor
Dependencies (16)
+ 8 more |
|
6.5.1
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.5.1
patch
Dependencies (16)
+ 8 more |
|
6.5.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.5.0
minor
Dependencies (16)
+ 8 more |
|
6.4.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.4.0
minor
Dependencies (17)
+ 9 more |
|
6.3.1
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.3.1
patch
Dependencies (17)
+ 9 more |
|
6.3.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.3.0
minor
Dependencies (17)
+ 9 more |
|
6.2.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.2.0
minor
Dependencies (15)
+ 7 more |
|
6.1.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.1.0
minor
Dependencies (15)
+ 7 more |
|
6.0.1
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.0.1
patch
Dependencies (15)
+ 7 more |
|
6.0.0
major
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
6.0.0
major
Dependencies (16)
+ 8 more |
|
5.5.1
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
5.5.1
patch
Dependencies (13)
+ 5 more |
|
5.5.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
5.5.0
minor
Dependencies (13)
+ 5 more |
|
5.4.1
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
5.4.1
patch
Dependencies (13)
+ 5 more |
|
5.4.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
5.4.0
minor
Dependencies (13)
+ 5 more |
|
5.3.1
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
5.3.1
patch
Dependencies (13)
+ 5 more |
|
5.3.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
5.3.0
minor
Dependencies (13)
+ 5 more |
|
5.2.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
5.2.0
minor
Dependencies (13)
+ 5 more |
|
5.1.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
5.1.0
minor
Dependencies (12)
+ 4 more |
|
5.0.0
major
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
5.0.0
major
Dependencies (12)
+ 4 more |
|
4.9.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
4.9.0
minor
Dependencies (11)
+ 3 more |
|
4.8.1
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
4.8.1
patch
Dependencies (11)
+ 3 more |
|
4.8.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
4.8.0
minor
Dependencies (11)
+ 3 more |
|
4.7.1
patch
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
4.7.1
patch
Dependencies (11)
+ 3 more |
|
4.7.0
minor
1 CVE
CVE-2026-54723
PYSEC-2026-3661
GHSA-m5pq-69xg-vcq3
Aug 19, 2026
devpi-server may leak database contents
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
Low
ImpactIf the replication protocol is enabled by using the The leaked hashes use the When Besides the information leak this can be used to produce significant CPU, IO and bandwidth usage depending on the database size. PatchesThe logic bug causing this issue is fixed with devpi-server 6.20.2 and devpi-server 7.0.0b3. WorkaroundsWhen replication isn't used the role can explicitly be set to If the server instance is exclusively served through Affected versions
0.7
0.8
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
+ 95 more Show less
1.0
1.1
1.2
1.2.1
1.2.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.1rc1
4.3.2
4.4.0
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.9.0
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.5.1
6.0.0
6.0.1
6.1.0
6.10.0
6.11.0
6.12.0
6.12.1
6.13.0
6.14.0
6.15.0
6.16.0
6.17.0
6.18.0
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.20.0
6.20.1
6.3.0
6.3.1
6.4.0
6.5.0
6.5.1
6.6.0
6.6.1
6.7.0
6.8.0
6.9.0
6.9.1
6.9.2
Fixed in
6.20.2
References Updated Aug 19, 2026 · Source: OSV.dev |
4.7.0
minor
Dependencies (11)
+ 3 more |