CVE-2026-21437

Source
https://cve.org/CVERecord?id=CVE-2026-21437
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21437.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-21437
Aliases
  • GHSA-hjp7-qwrj-6cc6
Published
2026-01-01T18:06:02.368Z
Modified
2026-08-12T03:51:18.171003632Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:H CVSS Calculator
Summary
eopkg vulnerable to package file list integrity bypass
Details

eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could include files that are not tracked by eopkg. This requires the installation of a package from a malicious or compromised source. Files in such packages would not be shown by lseopkg and related tools. The issue has been fixed in v4.4.0. Users only installing packages from the Solus repositories are not affected.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21437.json",
    "cwe_ids": [
        "CWE-353"
    ]
}
References

Affected packages

Git / github.com/getsolus/eopkg

Affected ranges

Type
GIT
Repo
https://github.com/getsolus/eopkg
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.4.0"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:getsol:eopkg:*:*:*:*:*:python:*:*"
}

Affected versions

v3.*
v3.1
v3.10
v3.2
v3.3
v3.4
v3.5
v3.6
v3.7
v3.8
v3.9
v4.*
v4.0-alpha1
v4.0.0
v4.1.0
v4.1.1
v4.1.2
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.2.0
v4.2.1
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21437.json"