PT-2026-86538 · Zenhive · Zenhive Mpp

·

CVE-2026-82750

·

Published

2026-09-06

·

Updated

2026-09-06

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZenHive mpp versions 0.2.0 through 0.16.0
Description Improper validation of input quantities allows an unauthenticated remote client to significantly increase the gas cost for a fee-payer during sponsored payments. The issue occurs when the server sponsors Tempo payments via the MPP.Methods.Tempo.FeePayerPolicy.measure/3 function in lib/mpp/methods/tempo/fee payer policy.ex. While the function bounds gas fields, fee budget, validity window, and the access list of the client-signed 0x76 envelope, it fails to read the aa authorization list field. Consequently, a client can attach delegations from throwaway authority keys, forcing the sponsor to pay the intrinsic gas for these delegations within the default gas limit ceiling. This can result in costs increasing from approximately 46,575 gas to 1,884,087 gas. Additionally, since each entry is applied as a persistent set-code delegation, a client can upgrade its own accounts to delegated code at the sponsor's expense.
Recommendations Update ZenHive mpp to version 0.16.1 or later. Disable Tempo fee sponsorship by setting fee payer to false and removing the fee payer url so the client pays its own gas. Lower the max gas override in fee payer policy to a value slightly above a legitimate sponsored payment (approximately 50,000 gas for a TIP-20 transfer) to bound the potential gas inflation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82750
GHSA-5QRP-R24C-W6JR

Affected Products

Zenhive Mpp