PT-2026-95003 · Mport · Mport

·

CVE-2026-54581

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mport versions prior to 2.7.8
Description The mport fetch bootstrap index() function in libmport/fetch.c fails to preserve a fatal result when bootstrap index hash verification encounters a missing or invalid hash, incorrectly returning success. This allows a network attacker or a compromised mirror to alter the bootstrap index content or its transport path, leading the system to use an unverified or tampered bootstrap package index.
Recommendations Update to version 2.7.8.

Exploit

Fix

Insufficient Verification of Data Authenticity

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54581
GHSA-895R-RV8J-7G23

Affected Products

Mport