CVE-2026-54586: mport permits repository and package mirror fetches over insecure transport

Published Sep 17, 2026
·
Updated

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mportfetchindex(), mportfetchbootstrapindex(), and mportfetchbundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without a urlishttps() enforcement check. When a cleartext URL was configured or returned by mirror data, a network-positioned attacker could tamper with package index or package download traffic and compromise package selection or integrity. This issue is fixed in version 2.7.8.

Affected Software

1 affected component
mport/libmport<2.7.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade mport (MidnightBSD Package Manager) to a version that resolves this vulnerability.

    Fixed in 2.7.8

Event History

Sep 17, 2026
CVE Published
via MITRE·04:53 PM
Data Sourced
via MITRE·04:53 PM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Systems running mport versions earlier than 2.7.8 are exposed when they use a repository or package mirror URL over cleartext transport. Exposure can arise from either a configured cleartext URL or mirror data that returns one.

2

What does an attacker need to exploit it?

An attacker must be in a network position to tamper with traffic between mport and the affected repository or package mirror. They could alter package index or package download traffic, affecting package selection or integrity.

3

What should be done if an immediate upgrade is not possible?

Avoid configuring non-HTTPS repository or package mirror URLs and do not use mirror data that directs mport to cleartext URLs. Upgrade to mport 2.7.8 when possible, which adds HTTPS enforcement in the affected fetch paths.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203