PT-2026-93378 · Zenhive · Zenhive Mpp
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ZenHive mpp versions 0.2.0 through 0.16.1
Description
Improper validation of unsafe equivalence in input allows an unauthenticated remote client to bypass the Tempo duplicate-submission gate twice using a single signed transaction. In
MPP.Methods.Tempo, the reserve hash atomic/2 function reserves the pre-broadcast deduplication slot based on the caller-supplied hex via store key/1 on tx.raw instead of using a canonical form of the transaction. Because the deserializer stores the hex verbatim and accepts both recovery-id encodings, a transaction submitted with v=27 and then with v=0 generates two distinct reserve keys, allowing both to reach the broadcast path. The credential replay store in lib/mpp/replay.ex is bypassed for tempo, leaving this reserve as the only protection. Depending on the node configuration, this can result in a nonce-reuse rejection or the issuance of a second valid Payment-Receipt for a single on-chain payment.Recommendations
Update ZenHive mpp to version 0.16.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zenhive Mpp