CVE-2026-21437
eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could include files that are not tracked by `eopkg`. This requires the installation of a package from a malicious or compromised source. Files in such packages would not be shown by `lseopkg` and related tools. The issue has been fixed in v4.4.0. Users only installing packages from the Solus repositories are not affected.
Scoring
- Severity
- LOW
- CVSS base score
- 2
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:H
- EPSS probability
- 0.17%
- CWE
- CWE-353
- Published
- 2026-01-01
- Last modified
- 2026-03-12
Affected products
- getsolus eopkg
Weakness type
Related vulnerabilities
- CVE-2026-89179 — Howyar|WeenyGenius - Missing Support for Integrity Check
- CVE-2026-81049 — Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check...
- CVE-2026-58224 — Samba: ctdb fails to do integrity checking of received packets
- CVE-2026-17583 — Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check
- CVE-2026-18536 — Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP
- CVE-2026-12705 — Integrity mechanism of KNX-device FW-files can be bypassed in ABB Update Tool
- CVE-2026-48995 — pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
- CVE-2026-7574 — Anthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use