Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 04 Mar 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getsol
Getsol eopkg |
|
| CPEs | cpe:2.3:a:getsol:eopkg:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Getsol
Getsol eopkg |
|
| Metrics |
cvssV3_1
|
Fri, 02 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could include files that are not tracked by `eopkg`. This requires the installation of a package from a malicious or compromised source. Files in such packages would not be shown by `lseopkg` and related tools. The issue has been fixed in v4.4.0. Users only installing packages from the Solus repositories are not affected. | |
| Title | eopkg vulnerable to package file list integrity bypass | |
| Weaknesses | CWE-353 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-02T18:54:21.061Z
Reserved: 2025-12-29T03:00:29.275Z
Link: CVE-2026-21437
Updated: 2026-01-02T18:54:13.816Z
Status : Analyzed
Published: 2026-01-01T18:15:41.347
Modified: 2026-03-04T21:31:50.400
Link: CVE-2026-21437
No data.
OpenCVE Enrichment
Updated: 2026-04-18T08:45:41Z