PT-2026-93379 · Zenhive · Zenhive Mpp

·

CVE-2026-89186

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZenHive mpp versions 0.1.0 through 0.16.1
Description ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients who have not paid. This occurs because the MPP.Plug.verify credential function in lib/mpp/plug.ex sets the payment-receipt and cache-control: private headers before the wrapped application runs, but does not register a register before send/2 callback. Since Plug.Conn.put resp header/3 replaces existing headers, any mounting application that sets its own cache-control (such as public, max-age=3600) overrides the private directive. Consequently, a CDN or reverse proxy may store the paid response and its Payment-Receipt header, serving them to unpaid clients. Additionally, non-2xx responses may still carry a Payment-Receipt, issuing a receipt for a response that delivered no resource.
Recommendations Update ZenHive mpp to version 0.16.2 or later. In the application mounted behind MPP.Plug, stop setting Cache-Control on paid routes or use safe directives such as private or no-store. Configure the CDN or reverse proxy to avoid caching responses that contain a Payment-Receipt header.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89186
GHSA-82QH-VRVM-GQVC

Affected Products

Zenhive Mpp