Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-vj8p-hp9x-gh47
  • Hex/mpp
mpp vulnerable to Gas Draining with low gas limit 4 days ago
  • Fix available
  • Severity - 8.8 (High)
GHSA-qpxh-ff8m-c62v
  • Hex/mpp
mpp vulnerable to Gas Draining with access list 4 days ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-vv77-66rf-pm86
  • Hex/mpp
mpp vulnerable to Gas Draining with no limit 4 days ago
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-87119
  • github.com/zenhive/mpp
mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed 22 Sep
  • Fix available
  • Severity - 8.2 (High)
EEF-CVE-2026-87119
  • Hex/mpp
  • github.com/zenhive/mpp
mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed 22 Sep
  • Fix available
  • Severity - 8.2 (High)
CVE-2026-89420
  • github.com/zenhive/mpp
Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free 22 Sep
  • Fix available
  • Severity - 7.1 (High)
EEF-CVE-2026-89420
  • Hex/mpp
  • github.com/zenhive/mpp
Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free 22 Sep
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-88255
  • github.com/zenhive/mpp
mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot 16 Sep
  • Fix available
  • Severity - 6.3 (Medium)
EEF-CVE-2026-88255
  • Hex/mpp
  • github.com/zenhive/mpp
mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot 16 Sep
  • Fix available
  • Severity - 6.3 (Medium)
CVE-2026-89186
  • github.com/zenhive/mpp
mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches 16 Sep
  • Fix available
  • Severity - 6.3 (Medium)
EEF-CVE-2026-89186
  • Hex/mpp
  • github.com/zenhive/mpp
mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches 16 Sep
  • Fix available
  • Severity - 6.3 (Medium)
CVE-2026-82750
  • github.com/zenhive/mpp
Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation 06 Sep
  • Fix available
  • Severity - 8.3 (High)
EEF-CVE-2026-82750
  • Hex/mpp
  • github.com/zenhive/mpp
Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation 06 Sep
  • Fix available
  • Severity - 8.3 (High)
CVE-2026-82751
  • github.com/zenhive/mpp
Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning 06 Sep
  • Fix available
  • Severity - 8.3 (High)
EEF-CVE-2026-82751
  • Hex/mpp
  • github.com/zenhive/mpp
Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning 06 Sep
  • Fix available
  • Severity - 8.3 (High)
CVE-2026-67581
  • github.com/zenhive/mpp
On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay 19 Aug
  • Fix available
  • Severity - 8.7 (High)