PT-2026-78538 · Zenhive · Zenhive Mpp
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ZenHive mpp versions 0.2.0 through 0.11.0
Description
An unauthenticated remote client can drain the fee-payer wallet by initiating concurrent sponsored payments, leading to a denial of service for legitimate payers. The issue occurs because
MPP.Methods.Tempo.FeePayerPolicy enforces budget ceilings—including max gas, max fee per gas, max priority fee per gas, and the max total fee budget cap—on a per-transaction basis rather than across concurrent requests. While the reserve hash atomic/2 function prevents the duplicate broadcast of the same signed transaction, it does not prevent multiple distinct sponsored transactions with different expiring nonces. Consequently, the total sponsor exposure can reach N times the max total fee, and the default 900-second validity window allows these transactions to remain broadcastable and uncounted.Recommendations
Update ZenHive mpp to version 0.12.0.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zenhive Mpp