VulnSea

mport vulnerabilities

CVEs whose affected-version data names the mport package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

13 CVEsRSS

CVE-2026-54584Medium· 5.3
today

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport …

SunlitMidnightBSD · mportvia NVD
CVE-2026-54587Medium· 5.8
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local a…

SunlitMidnightBSD · mportEPSS 0.10%via NVD
CVE-2026-54586Medium· 6.0
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without a url_is_h…

SunlitMidnightBSD · mportEPSS 0.13%via NVD
CVE-2026-54585Medium· 6.0
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malici…

SunlitMidnightBSD · mportEPSS 0.52%via NVD
CVE-2026-54583High· 8.3
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index d…

TwilightMidnightBSD · mportEPSS 0.52%via NVD
CVE-2026-54582Medium· 6.0
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/in…

SunlitMidnightBSD · mportEPSS 0.53%via NVD
CVE-2026-54581High· 8.3
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failur…

TwilightMidnightBSD · mportEPSS 0.21%via NVD
CVE-2026-54580High· 8.3
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently propagate those failures t…

TwilightMidnightBSD · mportEPSS 0.25%via NVD
CVE-2026-54579Low· 2.3
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using a fixed IP-header offset instead of ip_hl. A network attacker abl…

SunlitMidnightBSD · mportEPSS 0.14%via NVD
CVE-2026-54578Low· 2.0
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than …

SunlitMidnightBSD · mportEPSS 0.11%via NVD
CVE-2026-54577Low· 2.0
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument entry to audit_package(). When an operator or automat…

SunlitMidnightBSD · mportEPSS 0.15%via NVD
CVE-2026-54576Medium· 5.8
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with wr…

SunlitMidnightBSD · mportEPSS 0.10%via NVD
CVE-2026-54575Medium· 5.8
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle_read_install_pkg.c…

SunlitMidnightBSD · mportEPSS 0.12%via NVD
mport vulnerabilities (CVEs) · VulnSea