MidnightBSD mport

13 known vulnerabilities in MidnightBSD mport, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-54584 CVSS 5.3 medium mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as…
  • CVE-2026-54587 CVSS 5.8 medium mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in…
  • CVE-2026-54586 CVSS 6.0 medium mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle()…
  • CVE-2026-54585 CVSS 6.0 medium mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain…
  • CVE-2026-54583 CVSS 8.3 high mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or…
  • CVE-2026-54582 CVSS 6.0 medium mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets…
  • CVE-2026-54581 CVSS 8.3 high mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return…
  • CVE-2026-54580 CVSS 8.3 high mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream…
  • CVE-2026-54579 CVSS 2.3 low mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or…
  • CVE-2026-54578 CVSS 2.0 low mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or…
  • CVE-2026-54577 CVSS 2.0 low mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and…
  • CVE-2026-54576 CVSS 5.8 medium mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based…
  • CVE-2026-54575 CVSS 5.8 medium mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path…