Description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without a url_is_https() enforcement check. When a cleartext URL was configured or returned by mirror data, a network-positioned attacker could tamper with package index or package download traffic and compromise package selection or integrity. This issue is fixed in version 2.7.8.
Published: 2026-09-17
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Compromise of package integrity and selection
Action: Update package manager
AI Analysis

Impact

The mport installer functions failed to enforce HTTPS only URLs when fetching package indexes and bundles. As a result, any repository or mirror URL that used cleartext HTTP could be intercepted and altered by a network‑positioned attacker, allowing tampering with package metadata or delivering malicious package binaries. This flaw permits an attacker to compromise package selection or the integrity of installed software on the host.

Affected Systems

The problem exists in MidnightBSD’s package manager, mport, before version 2.7.8. Any system running a pre‑2.7.8 build of mport that uses HTTP or non‑HTTPS URLs for package repositories or mirrors is affected.

Risk and Exploitability

The CVSS base score of 6 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to be positioned on the network path between the host and the remote repository or mirror and to supply HTTP URLs for those sources. Once positioned, the attacker can modify the index or package data because the code accepted non‑HTTPS URLs without validation. The attack does not require elevated privileges on the target system, making it relatively straightforward if network control is achieved.

Generated by OpenCVE AI on September 19, 2026 at 03:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade mport to version 2.7.8 or newer, which adds HTTPS enforcement for repository and mirror URLs.
  • If an immediate upgrade is not possible, reconfigure all repository and mirror entries to use HTTPS URLs only and remove any existing HTTP entries.
  • Audit the repository configuration on all systems to verify no insecure URLs are present after the upgrade or reconfiguration.

Generated by OpenCVE AI on September 19, 2026 at 03:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Midnightbsd
Midnightbsd mport
Vendors & Products Midnightbsd
Midnightbsd mport

Thu, 17 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without a url_is_https() enforcement check. When a cleartext URL was configured or returned by mirror data, a network-positioned attacker could tamper with package index or package download traffic and compromise package selection or integrity. This issue is fixed in version 2.7.8.
Title mport permits repository and package mirror fetches over insecure transport
Weaknesses CWE-319
CWE-345
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Midnightbsd Mport
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:57:35.734Z

Reserved: 2026-06-15T19:15:27.344Z

Link: CVE-2026-54586

cve-icon Vulnrichment

Updated: 2026-09-21T20:57:31.219Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T17:16:43.883

Modified: 2026-09-21T21:17:04.840

Link: CVE-2026-54586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:15:16Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information

  • CWE-345

    Insufficient Verification of Data Authenticity