๐Ÿ” CVE Alert

CVE-2026-54581

UNKNOWN 0.0

mport bootstrap index fetch can continue after hash verification failure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failure path did not preserve a fatal result. A network attacker or compromised mirror able to alter bootstrap index content or its transport path could therefore cause mport to proceed with an unverified or tampered bootstrap package index. This issue is fixed in version 2.7.8.

CWE CWE-345 CWE-347
Vendor midnightbsd
Product mport
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for midnightbsd mport

Be the first to know when new unknown vulnerabilities affecting midnightbsd mport are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MidnightBSD / mport
< 2.7.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MidnightBSD/mport/security/advisories/GHSA-895r-rv8j-7g23 github.com: https://github.com/MidnightBSD/mport/pull/134 github.com: https://github.com/MidnightBSD/mport/pull/135 github.com: https://github.com/MidnightBSD/mport/commit/64ebf3f60dc3df72a3b47fbb20a7f8072c0a0f5e github.com: https://github.com/MidnightBSD/mport/commit/b3e11ba078351402082a881209ee6fda5d332e3d github.com: https://github.com/MidnightBSD/mport/releases/tag/2.7.8