Midnightbsd · Mport · CVE-2026-54580
**Name of the Vulnerable Software and Affected Versions**
mport versions prior to 2.7.8
**Description**
The MidnightBSD Package Manager fails to treat all truncated, corrupt, or failed zstd streams as fatal within the `mport decompress zstd()` function. Additionally, the `libmport/fetch.c` component does not consistently propagate these failures to index-fetch callers. A malicious or faulty mirror could provide compressed package index data that causes `ZSTD decompressStream()` or an output write to fail, leaving partial index output available. This can lead to package-index integrity loss or a denial of service.
**Recommendations**
Update to version 2.7.8.