Denial of Service Vulnerability in MidnightBSD Package Manager
CVE-2026-54580

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54580?

The MidnightBSD Package Manager contains a vulnerability where certain failures related to zstd stream decompression were not properly handled. Consequently, a malicious or compromised mirror could potentially deliver compromised package index data. This could result in failures during the decompression process, leading to partial output remaining available, which may compromise package-index integrity or cause denial of service. The issue has been addressed in version 2.7.8 of the MidnightBSD Package Manager.

Affected Version(s)

mport < 2.7.8

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.