Search

Find a vulnerability

Search criteria

    13 vulnerabilities by MidnightBSD

    CVE-2026-54584 (GCVE-0-2026-54584)

    Vulnerability from cvelistv5 – Published: 2026-09-21 14:05 – Updated: 2026-09-25 19:23
    VLAI
    Title
    mport trusts environment-controlled temporary directories in privileged metadata extraction
    Summary
    mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could redirect temporary metadata extraction to an attacker-controlled location. PR 123 ignores unsafe TMPDIR values in privileged contexts and rejects empty TMPDIR. This issue has been patched in version 2.7.8.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-25 19:23 UTC
    CWE
    • CWE-73 - External Control of File Name or Path
    • CWE-377 - Insecure Temporary File
    Impacted products
    Vendor Product Version
    MidnightBSD mport Affected: < 2.7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54584",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-25T19:23:03.329673Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-25T19:23:13.124Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "mport",
              "vendor": "MidnightBSD",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.7.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could redirect temporary metadata extraction to an attacker-controlled location. PR 123 ignores unsafe TMPDIR values in privileged contexts and rejects empty TMPDIR. This issue has been patched in version 2.7.8."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73: External Control of File Name or Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-377",
                  "description": "CWE-377: Insecure Temporary File",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-21T14:05:48.447Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-4vv3-3h8r-q6mq",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-4vv3-3h8r-q6mq"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/pull/123",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/pull/123"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/commit/3790fa49a36cb085f48b204ef189fb82bbee621a",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/commit/3790fa49a36cb085f48b204ef189fb82bbee621a"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8"
            }
          ],
          "source": {
            "advisory": "GHSA-4vv3-3h8r-q6mq",
            "discovery": "UNKNOWN"
          },
          "title": "mport trusts environment-controlled temporary directories in privileged metadata extraction"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54584",
        "datePublished": "2026-09-21T14:05:48.447Z",
        "dateReserved": "2026-06-15T19:15:27.344Z",
        "dateUpdated": "2026-09-25T19:23:13.124Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54579 (GCVE-0-2026-54579)

    Vulnerability from cvelistv5 – Published: 2026-09-17 16:59 – Updated: 2026-09-24 20:55
    VLAI
    Title
    mport mirror-selection ping accepts insufficiently validated ICMP replies
    Summary
    mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using a fixed IP-header offset instead of ip_hl. A network attacker able to inject or spoof visible ICMP replies could influence mirror latency selection, while a malformed packet carrying IP options could shift the ICMP header and trigger an out-of-bounds read. This issue is fixed in version 2.7.8.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 20:37 UTC
    CWE
    • CWE-125 - Out-of-bounds Read
    • CWE-345 - Insufficient Verification of Data Authenticity
    References
    Impacted products
    Vendor Product Version
    MidnightBSD mport Affected: < 2.7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54579",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T20:37:48.078385Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T20:55:22.592Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "mport",
              "vendor": "MidnightBSD",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.7.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using a fixed IP-header offset instead of ip_hl. A network attacker able to inject or spoof visible ICMP replies could influence mirror latency selection, while a malformed packet carrying IP options could shift the ICMP header and trigger an out-of-bounds read. This issue is fixed in version 2.7.8."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "ADJACENT",
                "baseScore": 2.3,
                "baseSeverity": "LOW",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125: Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-345",
                  "description": "CWE-345: Insufficient Verification of Data Authenticity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T16:59:52.147Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-qc2f-2j7j-m3r7",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-qc2f-2j7j-m3r7"
            }
          ],
          "source": {
            "advisory": "GHSA-qc2f-2j7j-m3r7",
            "discovery": "UNKNOWN"
          },
          "title": "mport mirror-selection ping accepts insufficiently validated ICMP replies"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54579",
        "datePublished": "2026-09-17T16:59:52.147Z",
        "dateReserved": "2026-06-15T19:15:27.344Z",
        "dateUpdated": "2026-09-24T20:55:22.592Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54576 (GCVE-0-2026-54576)

    Vulnerability from cvelistv5 – Published: 2026-09-17 16:58 – Updated: 2026-09-18 14:44
    VLAI
    Title
    mport package installation has symlink TOCTOU in chown and chmod handling
    Summary
    mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target directory could replace a checked file with a symlink before privileged ownership or mode changes were applied, redirecting those changes to an attacker-selected path and compromising filesystem integrity or permissions. This issue is fixed in version 2.7.8.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 14:36 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    Impacted products
    Vendor Product Version
    MidnightBSD mport Affected: < 2.7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54576",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T14:36:39.720536Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T14:44:36.712Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "mport",
              "vendor": "MidnightBSD",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.7.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target directory could replace a checked file with a symlink before privileged ownership or mode changes were applied, redirecting those changes to an attacker-selected path and compromising filesystem integrity or permissions. This issue is fixed in version 2.7.8."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59: Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T16:58:25.028Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-23g3-7fv3-3ccf",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-23g3-7fv3-3ccf"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/pull/150",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/pull/150"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/commit/4676ac05b1056b54a3d38d03ae8a478bf12c9abe",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/commit/4676ac05b1056b54a3d38d03ae8a478bf12c9abe"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8"
            }
          ],
          "source": {
            "advisory": "GHSA-23g3-7fv3-3ccf",
            "discovery": "UNKNOWN"
          },
          "title": "mport package installation has symlink TOCTOU in chown and chmod handling"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54576",
        "datePublished": "2026-09-17T16:58:25.028Z",
        "dateReserved": "2026-06-15T19:15:27.343Z",
        "dateUpdated": "2026-09-18T14:44:36.712Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54587 (GCVE-0-2026-54587)

    Vulnerability from cvelistv5 – Published: 2026-09-17 16:56 – Updated: 2026-09-17 19:15
    VLAI
    Title
    mport directory asset installation is vulnerable to symlink and path traversal races
    Summary
    mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local attacker able to modify part of the target installation tree could use dot-dot traversal or substitute symlinks during privileged package installation, causing directory creation or attribute changes to affect attacker-selected paths outside the intended package directories. This issue is fixed in version 2.7.8.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 19:14 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    Impacted products
    Vendor Product Version
    MidnightBSD mport Affected: < 2.7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54587",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T19:14:56.768674Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T19:15:12.857Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "mport",
              "vendor": "MidnightBSD",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.7.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local attacker able to modify part of the target installation tree could use dot-dot traversal or substitute symlinks during privileged package installation, causing directory creation or attribute changes to affect attacker-selected paths outside the intended package directories. This issue is fixed in version 2.7.8."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59: Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T16:56:33.174Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-f69w-h3gh-r86p",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-f69w-h3gh-r86p"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/pull/119",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/pull/119"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/commit/a4fa996df1fbebeff3691e1b512c807b5f414b5d",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/commit/a4fa996df1fbebeff3691e1b512c807b5f414b5d"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8"
            }
          ],
          "source": {
            "advisory": "GHSA-f69w-h3gh-r86p",
            "discovery": "UNKNOWN"
          },
          "title": "mport directory asset installation is vulnerable to symlink and path traversal races"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54587",
        "datePublished": "2026-09-17T16:56:33.174Z",
        "dateReserved": "2026-06-15T19:15:27.345Z",
        "dateUpdated": "2026-09-17T19:15:12.857Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54575 (GCVE-0-2026-54575)

    Vulnerability from cvelistv5 – Published: 2026-09-17 16:55 – Updated: 2026-09-21 20:58
    VLAI
    Title
    mport package fetch and clean paths are vulnerable to TOCTOU filesystem races
    Summary
    mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle_read_install_pkg.c, libmport/delete_primative.c, and libexec/mport.create/mport.create.c. A local attacker with write access to a participating package cache or staging path could race path checks and replacement operations to redirect package downloads, cleanup, or install-related side effects outside the intended cache. The affected lifecycle helper paths also used shell-form invocation, increasing command-line interpretation risk during privileged helper execution. This issue is fixed in version 2.7.8.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-21 20:58 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    Impacted products
    Vendor Product Version
    MidnightBSD mport Affected: < 2.7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54575",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-21T20:58:35.699318Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-21T20:58:45.216Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "mport",
              "vendor": "MidnightBSD",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.7.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle_read_install_pkg.c, libmport/delete_primative.c, and libexec/mport.create/mport.create.c. A local attacker with write access to a participating package cache or staging path could race path checks and replacement operations to redirect package downloads, cleanup, or install-related side effects outside the intended cache. The affected lifecycle helper paths also used shell-form invocation, increasing command-line interpretation risk during privileged helper execution. This issue is fixed in version 2.7.8."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T16:55:19.349Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-h387-g4pf-28cj",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-h387-g4pf-28cj"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/pull/118",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/pull/118"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/commit/29154b0fdfb5806568ed1277e88d942bad6d1169",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/commit/29154b0fdfb5806568ed1277e88d942bad6d1169"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8"
            }
          ],
          "source": {
            "advisory": "GHSA-h387-g4pf-28cj",
            "discovery": "UNKNOWN"
          },
          "title": "mport package fetch and clean paths are vulnerable to TOCTOU filesystem races"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54575",
        "datePublished": "2026-09-17T16:55:19.349Z",
        "dateReserved": "2026-06-15T19:15:27.343Z",
        "dateUpdated": "2026-09-21T20:58:45.216Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54578 (GCVE-0-2026-54578)

    Vulnerability from cvelistv5 – Published: 2026-09-17 16:54 – Updated: 2026-09-18 14:44
    VLAI
    Title
    mport verify can compare stale checksum data after hashing failures
    Summary
    mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than a newly computed digest. An attacker able to influence an installed file or the conditions that make hashing fail could receive a misleading integrity result or hide a checksum failure. This issue is fixed in version 2.7.8.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 14:36 UTC
    CWE
    • CWE-354 - Improper Validation of Integrity Check Value
    • CWE-755 - Improper Handling of Exceptional Conditions
    Impacted products
    Vendor Product Version
    MidnightBSD mport Affected: < 2.7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54578",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T14:36:37.692551Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T14:44:44.118Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "mport",
              "vendor": "MidnightBSD",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.7.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than a newly computed digest. An attacker able to influence an installed file or the conditions that make hashing fail could receive a misleading integrity result or hide a checksum failure. This issue is fixed in version 2.7.8."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 2,
                "baseSeverity": "LOW",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-354",
                  "description": "CWE-354: Improper Validation of Integrity Check Value",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-755",
                  "description": "CWE-755: Improper Handling of Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T16:54:20.195Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-hgmr-9p75-q5cg",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-hgmr-9p75-q5cg"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/pull/138",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/pull/138"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/commit/cd9991c3cc1f60ecb3f378852ad8b5caa820e990",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/commit/cd9991c3cc1f60ecb3f378852ad8b5caa820e990"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8"
            }
          ],
          "source": {
            "advisory": "GHSA-hgmr-9p75-q5cg",
            "discovery": "UNKNOWN"
          },
          "title": "mport verify can compare stale checksum data after hashing failures"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54578",
        "datePublished": "2026-09-17T16:54:20.195Z",
        "dateReserved": "2026-06-15T19:15:27.344Z",
        "dateUpdated": "2026-09-18T14:44:44.118Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54586 (GCVE-0-2026-54586)

    Vulnerability from cvelistv5 – Published: 2026-09-17 16:53 – Updated: 2026-09-21 20:57
    VLAI
    Title
    mport permits repository and package mirror fetches over insecure transport
    Summary
    mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without a url_is_https() enforcement check. When a cleartext URL was configured or returned by mirror data, a network-positioned attacker could tamper with package index or package download traffic and compromise package selection or integrity. This issue is fixed in version 2.7.8.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-21 20:57 UTC
    CWE
    • CWE-319 - Cleartext Transmission of Sensitive Information
    • CWE-345 - Insufficient Verification of Data Authenticity
    Impacted products
    Vendor Product Version
    MidnightBSD mport Affected: < 2.7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54586",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-21T20:57:25.913923Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-21T20:57:35.734Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "mport",
              "vendor": "MidnightBSD",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.7.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without a url_is_https() enforcement check. When a cleartext URL was configured or returned by mirror data, a network-positioned attacker could tamper with package index or package download traffic and compromise package selection or integrity. This issue is fixed in version 2.7.8."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "ADJACENT",
                "baseScore": 6,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-319",
                  "description": "CWE-319: Cleartext Transmission of Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-345",
                  "description": "CWE-345: Insufficient Verification of Data Authenticity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T16:53:24.229Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-v5pv-7gxw-74r5",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-v5pv-7gxw-74r5"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/pull/121",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/pull/121"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/commit/9b4d0f9192b243ee32266afa36dce430b257b921",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/commit/9b4d0f9192b243ee32266afa36dce430b257b921"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8"
            }
          ],
          "source": {
            "advisory": "GHSA-v5pv-7gxw-74r5",
            "discovery": "UNKNOWN"
          },
          "title": "mport permits repository and package mirror fetches over insecure transport"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54586",
        "datePublished": "2026-09-17T16:53:24.229Z",
        "dateReserved": "2026-06-15T19:15:27.344Z",
        "dateUpdated": "2026-09-21T20:57:35.734Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54585 (GCVE-0-2026-54585)

    Vulnerability from cvelistv5 – Published: 2026-09-17 16:52 – Updated: 2026-09-17 17:21
    VLAI
    Title
    mport sample file handling can write outside the configured root
    Summary
    mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malicious or malformed package manifest could therefore direct privileged sample-file handling to copy or write outside the configured installation root, compromising local filesystem integrity. This issue is fixed in version 2.7.8.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 17:21 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    MidnightBSD mport Affected: < 2.7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54585",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T17:21:08.742793Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T17:21:25.082Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "mport",
              "vendor": "MidnightBSD",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.7.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport-\u003eroot. A malicious or malformed package manifest could therefore direct privileged sample-file handling to copy or write outside the configured installation root, compromising local filesystem integrity. This issue is fixed in version 2.7.8."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T16:52:33.109Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-xqjc-rxmm-p27v",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-xqjc-rxmm-p27v"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/pull/122",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/pull/122"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/commit/36a42c8ddbd23ee9eb72c4c17596eb92cb423cf0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/commit/36a42c8ddbd23ee9eb72c4c17596eb92cb423cf0"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8"
            }
          ],
          "source": {
            "advisory": "GHSA-xqjc-rxmm-p27v",
            "discovery": "UNKNOWN"
          },
          "title": "mport sample file handling can write outside the configured root"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54585",
        "datePublished": "2026-09-17T16:52:33.109Z",
        "dateReserved": "2026-06-15T19:15:27.344Z",
        "dateUpdated": "2026-09-17T17:21:25.082Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54580 (GCVE-0-2026-54580)

    Vulnerability from cvelistv5 – Published: 2026-09-17 16:51 – Updated: 2026-09-24 20:55
    VLAI
    Title
    mport index decompression can leave partial or corrupt index data after zstd failures
    Summary
    mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently propagate those failures to index-fetch callers. A malicious or faulty mirror could supply compressed package index data that caused ZSTD_decompressStream() or an output write to fail while leaving partial index output available for later use, resulting in package-index integrity loss or denial of service. This issue is fixed in version 2.7.8.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 20:37 UTC
    CWE
    • CWE-354 - Improper Validation of Integrity Check Value
    • CWE-755 - Improper Handling of Exceptional Conditions
    Impacted products
    Vendor Product Version
    MidnightBSD mport Affected: < 2.7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54580",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T20:37:31.208937Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T20:55:22.459Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "mport",
              "vendor": "MidnightBSD",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.7.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently propagate those failures to index-fetch callers. A malicious or faulty mirror could supply compressed package index data that caused ZSTD_decompressStream() or an output write to fail while leaving partial index output available for later use, resulting in package-index integrity loss or denial of service. This issue is fixed in version 2.7.8."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-354",
                  "description": "CWE-354: Improper Validation of Integrity Check Value",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-755",
                  "description": "CWE-755: Improper Handling of Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T16:51:29.785Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-ffqj-j42r-747w",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-ffqj-j42r-747w"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/pull/135",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/pull/135"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/commit/b3e11ba078351402082a881209ee6fda5d332e3d",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/commit/b3e11ba078351402082a881209ee6fda5d332e3d"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8"
            }
          ],
          "source": {
            "advisory": "GHSA-ffqj-j42r-747w",
            "discovery": "UNKNOWN"
          },
          "title": "mport index decompression can leave partial or corrupt index data after zstd failures"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54580",
        "datePublished": "2026-09-17T16:51:29.785Z",
        "dateReserved": "2026-06-15T19:15:27.344Z",
        "dateUpdated": "2026-09-24T20:55:22.459Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54582 (GCVE-0-2026-54582)

    Vulnerability from cvelistv5 – Published: 2026-09-17 16:50 – Updated: 2026-09-17 19:15
    VLAI
    Title
    mport package installation can overwrite existing unmanaged or differently owned files
    Summary
    mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/install_primative.c, and libmport/mport_private.h did not apply MPORT_PRECHECK_FILE_CONFLICTS, so a crafted or conflicting package could overwrite a file owned by another package or unmanaged by mport. The check is bypassed only when the operator explicitly enables mport->force. Privileged installation without that override could compromise local filesystem integrity and package database consistency. This issue is fixed in version 2.7.8.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 19:15 UTC
    CWE
    • CWE-73 - External Control of File Name or Path
    • CWE-668 - Exposure of Resource to Wrong Sphere
    Impacted products
    Vendor Product Version
    MidnightBSD mport Affected: < 2.7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54582",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T19:15:39.206598Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T19:15:52.035Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "mport",
              "vendor": "MidnightBSD",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.7.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/install_primative.c, and libmport/mport_private.h did not apply MPORT_PRECHECK_FILE_CONFLICTS, so a crafted or conflicting package could overwrite a file owned by another package or unmanaged by mport. The check is bypassed only when the operator explicitly enables mport-\u003eforce. Privileged installation without that override could compromise local filesystem integrity and package database consistency. This issue is fixed in version 2.7.8."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73: External Control of File Name or Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-668",
                  "description": "CWE-668: Exposure of Resource to Wrong Sphere",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T16:50:40.434Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-5773-7r4r-rpgx",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-5773-7r4r-rpgx"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/pull/131",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/pull/131"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/commit/c643312d149dcc994957dbafa8f6f6b61e945e39",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/commit/c643312d149dcc994957dbafa8f6f6b61e945e39"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8"
            }
          ],
          "source": {
            "advisory": "GHSA-5773-7r4r-rpgx",
            "discovery": "UNKNOWN"
          },
          "title": "mport package installation can overwrite existing unmanaged or differently owned files"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54582",
        "datePublished": "2026-09-17T16:50:40.434Z",
        "dateReserved": "2026-06-15T19:15:27.344Z",
        "dateUpdated": "2026-09-17T19:15:52.035Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54577 (GCVE-0-2026-54577)

    Vulnerability from cvelistv5 – Published: 2026-09-17 16:49 – Updated: 2026-09-24 20:55
    VLAI
    Title
    mport audit can inspect the wrong package when options are present
    Summary
    mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument entry to audit_package(). When an operator or automation used an option such as -r before a package name, stale optind state and the unadjusted argument could cause mport to audit the option token instead of the requested package, producing a false-negative or useless result that could leave a vulnerable package unidentified. The corrected parsing resets optind and optreset before using the adjusted local arguments. This issue is fixed in version 2.7.8.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 20:37 UTC
    CWE
    • CWE-20 - Improper Input Validation
    • CWE-693 - Protection Mechanism Failure
    Impacted products
    Vendor Product Version
    MidnightBSD mport Affected: < 2.7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54577",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T20:37:11.506594Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T20:55:22.326Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "mport",
              "vendor": "MidnightBSD",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.7.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument entry to audit_package(). When an operator or automation used an option such as -r before a package name, stale optind state and the unadjusted argument could cause mport to audit the option token instead of the requested package, producing a false-negative or useless result that could leave a vulnerable package unidentified. The corrected parsing resets optind and optreset before using the adjusted local arguments. This issue is fixed in version 2.7.8."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 2,
                "baseSeverity": "LOW",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20: Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-693",
                  "description": "CWE-693: Protection Mechanism Failure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T16:49:48.323Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-h3m9-vj4v-c35h",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-h3m9-vj4v-c35h"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/pull/149",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/pull/149"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/commit/b897240dc8181c53fbee231e77f88657c1edb9a0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/commit/b897240dc8181c53fbee231e77f88657c1edb9a0"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8"
            }
          ],
          "source": {
            "advisory": "GHSA-h3m9-vj4v-c35h",
            "discovery": "UNKNOWN"
          },
          "title": "mport audit can inspect the wrong package when options are present"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54577",
        "datePublished": "2026-09-17T16:49:48.323Z",
        "dateReserved": "2026-06-15T19:15:27.344Z",
        "dateUpdated": "2026-09-24T20:55:22.326Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54583 (GCVE-0-2026-54583)

    Vulnerability from cvelistv5 – Published: 2026-09-17 16:46 – Updated: 2026-09-17 17:00
    VLAI
    Title
    mport package bundle downloads allow unsafe destination filenames
    Summary
    mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index data could place an unsafe value in indexEntry->bundlefile, and the missing is_valid_bundle_filename() checks allowed downloaded package data to be written outside the intended cache location or to an unsafe destination name. This issue is fixed in version 2.7.8.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 16:59 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    • CWE-73 - External Control of File Name or Path
    Impacted products
    Vendor Product Version
    MidnightBSD mport Affected: < 2.7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54583",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T16:59:46.851963Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T17:00:25.780Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "mport",
              "vendor": "MidnightBSD",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.7.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index data could place an unsafe value in indexEntry-\u003ebundlefile, and the missing is_valid_bundle_filename() checks allowed downloaded package data to be written outside the intended cache location or to an unsafe destination name. This issue is fixed in version 2.7.8."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73: External Control of File Name or Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T16:46:28.371Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-mr62-mqwj-vhh3",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-mr62-mqwj-vhh3"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/pull/125",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/pull/125"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/commit/cad959d47bc79a62b6a7163800fbfe35633e7cf8",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/commit/cad959d47bc79a62b6a7163800fbfe35633e7cf8"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8"
            }
          ],
          "source": {
            "advisory": "GHSA-mr62-mqwj-vhh3",
            "discovery": "UNKNOWN"
          },
          "title": "mport package bundle downloads allow unsafe destination filenames"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54583",
        "datePublished": "2026-09-17T16:46:28.371Z",
        "dateReserved": "2026-06-15T19:15:27.344Z",
        "dateUpdated": "2026-09-17T17:00:25.780Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54581 (GCVE-0-2026-54581)

    Vulnerability from cvelistv5 – Published: 2026-09-17 16:45 – Updated: 2026-09-17 19:17
    VLAI
    Title
    mport bootstrap index fetch can continue after hash verification failure
    Summary
    mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failure path did not preserve a fatal result. A network attacker or compromised mirror able to alter bootstrap index content or its transport path could therefore cause mport to proceed with an unverified or tampered bootstrap package index. This issue is fixed in version 2.7.8.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 19:17 UTC
    CWE
    • CWE-345 - Insufficient Verification of Data Authenticity
    • CWE-347 - Improper Verification of Cryptographic Signature
    Impacted products
    Vendor Product Version
    MidnightBSD mport Affected: < 2.7.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54581",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T19:17:03.686817Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T19:17:19.437Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "mport",
              "vendor": "MidnightBSD",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.7.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failure path did not preserve a fatal result. A network attacker or compromised mirror able to alter bootstrap index content or its transport path could therefore cause mport to proceed with an unverified or tampered bootstrap package index. This issue is fixed in version 2.7.8."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-345",
                  "description": "CWE-345: Insufficient Verification of Data Authenticity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-347",
                  "description": "CWE-347: Improper Verification of Cryptographic Signature",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T16:45:37.688Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-895r-rv8j-7g23",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/MidnightBSD/mport/security/advisories/GHSA-895r-rv8j-7g23"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/pull/134",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/pull/134"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/pull/135",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/pull/135"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/commit/64ebf3f60dc3df72a3b47fbb20a7f8072c0a0f5e",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/commit/64ebf3f60dc3df72a3b47fbb20a7f8072c0a0f5e"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/commit/b3e11ba078351402082a881209ee6fda5d332e3d",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/commit/b3e11ba078351402082a881209ee6fda5d332e3d"
            },
            {
              "name": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/MidnightBSD/mport/releases/tag/2.7.8"
            }
          ],
          "source": {
            "advisory": "GHSA-895r-rv8j-7g23",
            "discovery": "UNKNOWN"
          },
          "title": "mport bootstrap index fetch can continue after hash verification failure"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54581",
        "datePublished": "2026-09-17T16:45:37.688Z",
        "dateReserved": "2026-06-15T19:15:27.344Z",
        "dateUpdated": "2026-09-17T19:17:19.437Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }