PT-2026-95016 · Midnightbsd · Mport

·

CVE-2026-54586

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

6.0

Medium

VectorAV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions mport versions prior to 2.7.8
Description The MidnightBSD Package Manager fails to enforce HTTPS for repository and package mirror URLs within the mport fetch index(), mport fetch bootstrap index(), and mport fetch bundle() functions located in libmport/fetch.c. This lack of url is https() verification allows a network-positioned attacker to intercept and modify cleartext traffic during package index retrieval or package downloads, potentially compromising the integrity of the downloaded packages or the package selection process.
Recommendations Update to version 2.7.8.

Exploit

Fix

Insufficient Verification of Data Authenticity

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54586
GHSA-V5PV-7GXW-74R5

Affected Products

Mport