Mpp

ZenHive · 13 CVEs

CVE-2026-87119
HIGH

mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credenti…

Sep 22, 2026

CVE-2026-89420
HIGH

Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free

Sep 22, 2026

CVE-2026-88255
MEDIUM

mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed tran…

Sep 16, 2026

CVE-2026-89186
MEDIUM

mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Contro…

Sep 16, 2026

CVE-2026-82750
HIGH

Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegat…

Sep 6, 2026

CVE-2026-82751
HIGH

Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning

Sep 6, 2026

CVE-2026-67581
HIGH

On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay

Aug 19, 2026

CVE-2026-73541
HIGH

Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet dra…

Aug 19, 2026

CVE-2026-73136
HIGH

Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay

Aug 19, 2026

CVE-2026-73829
MEDIUM

Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race

Aug 19, 2026

CVE-2026-59252
HIGH

Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain

Jul 17, 2026

CVE-2026-59694
HIGH

Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment

Jul 17, 2026

CVE-2026-59695
HIGH

Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain

Jul 17, 2026

Showing 1 to 13 of 13 CVEs