CVE-2026-54581

high

Description

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failure path did not preserve a fatal result. A network attacker or compromised mirror able to alter bootstrap index content or its transport path could therefore cause mport to proceed with an unverified or tampered bootstrap package index. This issue is fixed in version 2.7.8.

References

https://github.com/MidnightBSD/mport/security/advisories/GHSA-895r-rv8j-7g23

https://github.com/MidnightBSD/mport/releases/tag/2.7.8

https://github.com/MidnightBSD/mport/pull/135

https://github.com/MidnightBSD/mport/pull/134

https://github.com/MidnightBSD/mport/commit/b3e11ba078351402082a881209ee6fda5d332e3d

https://github.com/MidnightBSD/mport/commit/64ebf3f60dc3df72a3b47fbb20a7f8072c0a0f5e

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-17

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: High

CVSS v4

Base Score: 8.3

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00209