VYPR

devpi

by Devpi

Source repositories

CVEs (1)

  • CVE-2026-54723MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.00

    devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +changelog route because verify_primary…