PT-2026-96975 · Mppx · Mppx
CVE-2026-63628
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
mppx versions prior to 0.8.2
Description
The fee-payer cosigning path in
src/tempo/internal/fee-payer.ts copies a client-supplied access list from a 0x78 FeePayerEnvelope without validating its length or contents. EIP-2930 access-list entries consume intrinsic gas—gas charged before any opcode executes—regardless of whether the listed addresses are used. A malicious client can include fabricated address-only entries in a transferWithMemo request, forcing the server fee-payer wallet to pay significantly higher transaction fees. For example, a list of 180 entries can increase the fee by approximately 9.4 times while remaining within the 500,000 gas policy cap, the 16 KB header limit, and the RPC simulation budget.Recommendations
Update mppx to version 0.8.2.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mppx