mpp
Hex9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mpppage 1 of 1
- CVE-2026-59252HIGHCVSS 8.2EG 8.2✓ Fixed in 0.6.02026-07-17
vulnerable: 0.2.0, 0.3.0, 0.3.1, 0.3.2, 0.4.0
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitimate clients. When the mpp Elixir library is configured as f…
- CVE-2026-59694HIGHCVSS 8.3EG 8.3✓ Fixed in 0.6.02026-07-17
vulnerable: 0.2.0, 0.3.0, 0.3.1, 0.3.2, 0.4.0
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multiplier, degrading the sponsor's operating margin. When the mpp Elixir…
- CVE-2026-59695HIGHCVSS 8.3EG 8.3✓ Fixed in 0.6.02026-07-17
vulnerable: 0.2.0, 0.3.0, 0.3.1, 0.3.2, 0.4.0
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price. When the mpp Elixir library is configured…
- CVE-2026-67581HIGHCVSS 7.5EG 7.5✓ Fixed in 0.6.32026-08-19
vulnerable: 0.3.0 ... 0.6.2 (7 versions)
Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matc…
- CVE-2026-73136HIGHCVSS 7.5EG 7.5✓ Fixed in 0.6.42026-08-19
vulnerable: 0.6.1, 0.6.2, 0.6.3
Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by replaying a transfer settled by an unrelated payer. MPP.Methods.Tempo normally binds a settled TIP-20 TransferWithMem…
- CVE-2026-73541HIGHCVSS 8.2EG 8.2✓ Fixed in 0.12.02026-08-19
vulnerable: 0.10.0 ... 0.9.0 (15 versions)
Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.Me…
- CVE-2026-73829LOWCVSS 3.7EG 3.7✓ Fixed in 0.6.12026-08-19
vulnerable: 0.2.0 ... 0.6.0 (6 versions)
Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses. The type="hash" credential path in MPP.Methods.Tempo.ve…
- CVE-2026-82750HIGHCVSS 8.3EG 8.3✓ Fixed in 0.16.12026-09-06
vulnerable: 0.10.0 ... 0.9.0 (20 versions)
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account dele…
- CVE-2026-82751HIGHCVSS 8.3EG 8.3✓ Fixed in 0.16.12026-09-06
vulnerable: 0.10.0 ... 0.9.0 (20 versions)
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an acces…
Check whether mpp is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mpp CVEs against the assets you own.
Start Free Scan →