Description
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price.

When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3 re-signs the client-supplied base fields of the 0x76 AASigned envelope verbatim, including max_fee_per_gas and max_priority_fee_per_gas, without validating that they are within reasonable bounds. A malicious client embeds arbitrarily large values for these fields in the signed envelope. The server co-signs and broadcasts the transaction. The effective_gas_price billed against the fee-payer wallet is derived from the attacker-supplied ceilings, so the server pays those inflated per-gas rates out of its own wallet. A single crafted request can drain the wallet entirely, after which the server can no longer sponsor gas for legitimate payment requests.

This issue affects mpp: from 0.2.0 before 0.6.0.
Published: 2026-07-17
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from improper validation of the max_fee_per_gas and max_priority_fee_per_gas parameters in the ZenHive mpp library. When the library is configured as a fee payer, it re-signs incoming transactions without checking that the gas ceilings are reasonable. A malicious client can embed arbitrarily large values for these fields; the server co-signs and broadcasts, billing itself at the inflated rates. This single request can exhaust the fee‑payer wallet, cutting off gas sponsorship for legitimate requests. The weakness is classified as CWE‑1284 and results in financial loss to the server operator.

Affected Systems

Affected vendors: ZenHive. Product: mpp library. Affected versions are 0.2.0 up to but not including 0.6.0. Versions 0.6.0 and later contain the fix that forces validation of gas price ceilings.

Risk and Exploitability

The CVSS score is 8.3, indicating high severity. The EPSS score is below 1 %, suggesting a low probability of exploitation under current data, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, because the attack requires only an unauthenticated request to a server configured as a fee payer, an attacker can drain the wallet with a single crafted transaction. The impact is loss of available funds and interruption of legitimate service. The low EPSS does not eliminate the risk in environments that expose the mpp library to the public; regular monitoring and prompt patching are prudent.

Generated by OpenCVE AI on July 31, 2026 at 00:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the ZenHive mpp library to version 0.6.0 or later, where gas price validation has been added.
  • If an upgrade is not immediately possible, disable the fee_payer feature by setting fee_payer: false to prevent the server from co-signing client-supplied envelopes.
  • Implement transaction monitoring and logging for the fee‑payer wallet, and consider setting a low maximum offset for max_fee_per_gas and max_priority_fee_per_gas to limit potential loss.

Generated by OpenCVE AI on July 31, 2026 at 00:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Zenhive
Zenhive mpp
Vendors & Products Zenhive
Zenhive mpp

Fri, 17 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Description Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price. When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3 re-signs the client-supplied base fields of the 0x76 AASigned envelope verbatim, including max_fee_per_gas and max_priority_fee_per_gas, without validating that they are within reasonable bounds. A malicious client embeds arbitrarily large values for these fields in the signed envelope. The server co-signs and broadcasts the transaction. The effective_gas_price billed against the fee-payer wallet is derived from the attacker-supplied ceilings, so the server pays those inflated per-gas rates out of its own wallet. A single crafted request can drain the wallet entirely, after which the server can no longer sponsor gas for legitimate payment requests. This issue affects mpp: from 0.2.0 before 0.6.0.
Title Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain
First Time appeared Zenhive
Zenhive mpp
Weaknesses CWE-1284
CPEs cpe:2.3:a:ZenHive:mpp:*:*:*:*:*:*:*:*
Vendors & Products Zenhive
Zenhive mpp
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-07-18T04:12:26.916Z

Reserved: 2026-07-06T14:05:47.003Z

Link: CVE-2026-59695

cve-icon Vulnrichment

Updated: 2026-07-17T12:52:53.192Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:45:05Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input