Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
CVE-2026-59252: ZenHive mpp can be forced to pay gas for free
CVE-2026-59252 · published 14 days ago
Summary
The ZenHive mpp service can be tricked into paying transaction fees even when the client does not provide enough gas. An attacker can submit requests with a slightly low gas limit, causing the service to broadcast the transaction, run out of gas, and charge the service’s wallet while the attacker pays nothing. To protect yourself, update to a version that checks the gas limit before signing or add your own validation to reject low‑gas requests.
What to do
- Update mpp to version 0.6.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | zenhive | mpp |
< 0.6.0 < d84e3e528db39654540c2035ea0fbdf7b950d3d1 |
| Hex | – | mpp |
>= 0.2.0, < 0.6.0 Fix: upgrade to 0.6.0
|
Original advisory text
mpp vulnerable to Gas Draining with low gas limit
## Vulnerability
When the server acts as the fee payer, `mpp` Elixir 0.4.0 (ZenHive/mpp) does not validate whether the `gas_limit` set by the client is enough before broadcasting. A malicious client can drain the server's gas without paying.
A `transferWithMemo` call on Tempo Moderato testnet requires **~51,299 gas** to complete successfully. By setting `gas_limit = 51,298`:
1. The Tx gets cosigned and broadcast by the server.
2. The Tx runs out of gas during EVM execution. All state reverts.
3. The server's fee-payer wallet is charged for gas used.
4. The client pays nothing and receives no resource.
```bash
# Run the PoC
unzip mpp_elixir_low_gas_PoC.zip
cd mpp_elixir_low_gas_PoC
docker build -t mpp-elixir-low-gas .
docker run --rm mpp-elixir-low-gas
```
**Zero-Cost DoS Attack:** Unlike gas draining with `access list` or `padding`, where the malicious client needs to complete a payment to drain the gas, this vulnerability allows malicious users to continuously drain the server's gas at virtually no financial cost (requiring only computing power). Therefore, an attacker can spawn *N* malicious clients to completely drain the funds from the server's wallet to perform a Denial of Service (DoS) attack. Once the server's wallet is empty, it has no more funds to pay the gas fees for upcoming requests from legitimate clients.
```bash
# Run the DoS PoC
unzip mpp_elixir_low_gas_dos_PoC.zip
cd mpp_elixir_low_gas_dos_PoC
docker build -t mpp-elixir-dos .
docker run --rm mpp-elixir-dos
```
**Vulnerable code path:** `broadcast_and_verify/7` in `mpp/methods/tempo.ex` (ZenHive/mpp 0.4.0).
When `wait_for_confirmation = true` (the default), it calls `rpc_broadcast_sync` directly without any gas-adequacy check or simulation. The alternative `wait_for_confirmation = false` path does call `simulate_payment_call` via `eth_call`, but that simulation omits the `gas` parameter and therefore does not catch out-of-gas conditions.
## Impact
A malicious client can drain the server's wallet without any financial cost.
When the server acts as the fee payer, `mpp` Elixir 0.4.0 (ZenHive/mpp) does not validate whether the `gas_limit` set by the client is enough before broadcasting. A malicious client can drain the server's gas without paying.
A `transferWithMemo` call on Tempo Moderato testnet requires **~51,299 gas** to complete successfully. By setting `gas_limit = 51,298`:
1. The Tx gets cosigned and broadcast by the server.
2. The Tx runs out of gas during EVM execution. All state reverts.
3. The server's fee-payer wallet is charged for gas used.
4. The client pays nothing and receives no resource.
```bash
# Run the PoC
unzip mpp_elixir_low_gas_PoC.zip
cd mpp_elixir_low_gas_PoC
docker build -t mpp-elixir-low-gas .
docker run --rm mpp-elixir-low-gas
```
**Zero-Cost DoS Attack:** Unlike gas draining with `access list` or `padding`, where the malicious client needs to complete a payment to drain the gas, this vulnerability allows malicious users to continuously drain the server's gas at virtually no financial cost (requiring only computing power). Therefore, an attacker can spawn *N* malicious clients to completely drain the funds from the server's wallet to perform a Denial of Service (DoS) attack. Once the server's wallet is empty, it has no more funds to pay the gas fees for upcoming requests from legitimate clients.
```bash
# Run the DoS PoC
unzip mpp_elixir_low_gas_dos_PoC.zip
cd mpp_elixir_low_gas_dos_PoC
docker build -t mpp-elixir-dos .
docker run --rm mpp-elixir-dos
```
**Vulnerable code path:** `broadcast_and_verify/7` in `mpp/methods/tempo.ex` (ZenHive/mpp 0.4.0).
When `wait_for_confirmation = true` (the default), it calls `rpc_broadcast_sync` directly without any gas-adequacy check or simulation. The alternative `wait_for_confirmation = false` path does call `simulate_payment_call` via `eth_call`, but that simulation omits the `gas` parameter and therefore does not catch out-of-gas conditions.
## Impact
A malicious client can drain the server's wallet without any financial cost.
References
- https://github.com URL
- https://repo.hex.pm URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59252... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-59252 Vendor Advisory
- https://cna.erlef.org/cves/CVE-2026-59252.html URL
- https://github.com/ZenHive/mpp/commit/d84e3e528db39654540c2035ea0fbdf7b950d3d1 Patch
- https://github.com/ZenHive/mpp Product
- https://github.com/ZenHive/mpp/releases/tag/v0.6.0 URL
- https://osv.dev/vulnerability/EEF-CVE-2026-59252 URL
- https://github.com/ZenHive/mpp/security/advisories/GHSA-vj8p-hp9x-gh47 Vendor Advisory
Internet-facing
60 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker partial control
Severity
8.8
High
Type
CWE-1284Improper Validation of Specified Quantity in Input
CWE-20Improper Input Validation
Timeline
Published25 Sep 2026
Updated9 Oct 2026
First seen17 Jul 2026
Track software like this
Free during beta