PT-2026-96975 · Mppx · Mppx

CVE-2026-63628

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions mppx versions prior to 0.8.2
Description The fee-payer cosigning path in src/tempo/internal/fee-payer.ts copies a client-supplied access list from a 0x78 FeePayerEnvelope without validating its length or contents. EIP-2930 access-list entries consume intrinsic gas—gas charged before any opcode executes—regardless of whether the listed addresses are used. A malicious client can include fabricated address-only entries in a transferWithMemo request, forcing the server fee-payer wallet to pay significantly higher transaction fees. For example, a list of 180 entries can increase the fee by approximately 9.4 times while remaining within the 500,000 gas policy cap, the 16 KB header limit, and the RPC simulation budget.
Recommendations Update mppx to version 0.8.2.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63628
GHSA-VC9J-9WPH-QGHJ

Affected Products

Mppx