PT-2026-78538 · Zenhive · Zenhive Mpp

·

CVE-2026-73541

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZenHive mpp versions 0.2.0 through 0.11.0
Description An unauthenticated remote client can drain the fee-payer wallet by initiating concurrent sponsored payments, leading to a denial of service for legitimate payers. The issue occurs because MPP.Methods.Tempo.FeePayerPolicy enforces budget ceilings—including max gas, max fee per gas, max priority fee per gas, and the max total fee budget cap—on a per-transaction basis rather than across concurrent requests. While the reserve hash atomic/2 function prevents the duplicate broadcast of the same signed transaction, it does not prevent multiple distinct sponsored transactions with different expiring nonces. Consequently, the total sponsor exposure can reach N times the max total fee, and the default 900-second validity window allows these transactions to remain broadcastable and uncounted.
Recommendations Update ZenHive mpp to version 0.12.0.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73541
GHSA-J4J7-7XPR-C7CR

Affected Products

Zenhive Mpp