Mpp
ZenHive · 13 CVEs
mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credenti…
Sep 22, 2026
Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free
Sep 22, 2026
mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed tran…
Sep 16, 2026
mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Contro…
Sep 16, 2026
Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegat…
Sep 6, 2026
Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning
Sep 6, 2026
On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay
Aug 19, 2026
Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet dra…
Aug 19, 2026
Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay
Aug 19, 2026
Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race
Aug 19, 2026
Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain
Jul 17, 2026
Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment
Jul 17, 2026
Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain
Jul 17, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-87119 | mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed | HIGH | 0.57% | Sep 22, 2026 |
| CVE-2026-89420 | Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free | HIGH | 0.41% | Sep 22, 2026 |
| CVE-2026-88255 | mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot | MEDIUM | 0.52% | Sep 16, 2026 |
| CVE-2026-89186 | mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches | MEDIUM | 0.52% | Sep 16, 2026 |
| CVE-2026-82750 | Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation | HIGH | 0.52% | Sep 6, 2026 |
| CVE-2026-82751 | Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning | HIGH | 0.52% | Sep 6, 2026 |
| CVE-2026-67581 | On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay | HIGH | 0.60% | Aug 19, 2026 |
| CVE-2026-73541 | Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain | HIGH | 0.59% | Aug 19, 2026 |
| CVE-2026-73136 | Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay | HIGH | 0.60% | Aug 19, 2026 |
| CVE-2026-73829 | Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race | MEDIUM | 0.32% | Aug 19, 2026 |
| CVE-2026-59252 | Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain | HIGH | 0.63% | Jul 17, 2026 |
| CVE-2026-59694 | Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment | HIGH | 0.52% | Jul 17, 2026 |
| CVE-2026-59695 | Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain | HIGH | 0.52% | Jul 17, 2026 |
Showing 1 to 13 of 13 CVEs