CVE-2026-54581
mport bootstrap index fetch can continue after hash verification failure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failure path did not preserve a fatal result. A network attacker or compromised mirror able to alter bootstrap index content or its transport path could therefore cause mport to proceed with an unverified or tampered bootstrap package index. This issue is fixed in version 2.7.8.
| CWE | CWE-345 CWE-347 |
| Vendor | midnightbsd |
| Product | mport |
| Published | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for midnightbsd mport
Be the first to know when new unknown vulnerabilities affecting midnightbsd mport are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
MidnightBSD / mport
< 2.7.8
References
github.com: https://github.com/MidnightBSD/mport/security/advisories/GHSA-895r-rv8j-7g23 github.com: https://github.com/MidnightBSD/mport/pull/134 github.com: https://github.com/MidnightBSD/mport/pull/135 github.com: https://github.com/MidnightBSD/mport/commit/64ebf3f60dc3df72a3b47fbb20a7f8072c0a0f5e github.com: https://github.com/MidnightBSD/mport/commit/b3e11ba078351402082a881209ee6fda5d332e3d github.com: https://github.com/MidnightBSD/mport/releases/tag/2.7.8