mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently propagate those failures to index-fetch callers. A malicious or faulty mirror could supply compressed package index data that caused ZSTD_decompressStream() or an output write to fail while leaving partial index output available for later use, resulting in package-index integrity loss or denial of service. This issue is fixed in version 2.7.8.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-354",
"CWE-755"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54580.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54580.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"273663711616624712904137650099031571974",
"294425045695914500674190171101965667096",
"87852885090537957491565621854760744324",
"182138002652916283422132749411705081273",
"133891235758763390135025935315507429585",
"338853542523308733483014684765343142728",
"207199073745177706665489780604859751366",
"122092128584208768294794609550683178198",
"337858432402960559802823748189594911313",
"221843752473596697732056465781662527261",
"142297238949626874537383624799227340961",
"91057373537920558804273305304659679011",
"257660415420928539487168048420879924442",
"68255568272259003946998349206003701392",
"311791982136376080149514111693465292710",
"265018424889668156976643022915695394469",
"112800010796803087182615053341756372216"
],
"threshold": 0.9
},
"id": "CVE-2026-54580-1e377afe",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/b3e11ba078351402082a881209ee6fda5d332e3d",
"target": {
"file": "libmport/util.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "228860771419624533693889587099451733372",
"length": 1724
},
"id": "CVE-2026-54580-9697aa24",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/b3e11ba078351402082a881209ee6fda5d332e3d",
"target": {
"file": "libmport/util.c",
"function": "mport_decompress_zstd"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "209395942731077130336847032314305746970",
"length": 1848
},
"id": "CVE-2026-54580-bf826610",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/b3e11ba078351402082a881209ee6fda5d332e3d",
"target": {
"file": "libmport/fetch.c",
"function": "mport_fetch_index"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "168883938179142272866881669702208103556",
"length": 1165
},
"id": "CVE-2026-54580-c0a107f3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/b3e11ba078351402082a881209ee6fda5d332e3d",
"target": {
"file": "libmport/fetch.c",
"function": "mport_fetch_bootstrap_index"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"28155665265217389570373726260696265733",
"270546140310395727864820072664402228878",
"17189134069191075523197834239154910312",
"44484155967387362857806185456147595087",
"252824991807596761603464753526964202824",
"242500639577386535065508131056626515885",
"94449469585795167323269339478392859836",
"45325448920302085866589026156451866140",
"7449633375845181586455225165922152434",
"287251875171957920869938498977625021603",
"139701436355309232264874963606483723538",
"13139320937628813329424206767234075353",
"122491412888024131315075349147469244866"
],
"threshold": 0.9
},
"id": "CVE-2026-54580-fa360697",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/b3e11ba078351402082a881209ee6fda5d332e3d",
"target": {
"file": "libmport/fetch.c"
}
}
]
"2026-09-26T08:12:52Z"