Vulnerability in MidnightBSD Package Manager Affects Bootstrap Index Verification
CVE-2026-54581

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54581?

The MidnightBSD Package Manager contains a vulnerability in the mport_fetch_bootstrap_index() function, which fails to properly verify the bootstrap index hash before proceeding with operations. This oversight could potentially allow an attacker to manipulate the bootstrap index, leading to the installation of unverified or malicious packages. Users are encouraged to upgrade to version 2.7.8 or later to mitigate this risk. The identified vulnerability emphasizes the importance of strict hash verification during package management processes.

Affected Version(s)

mport < 2.7.8

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.