Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-59695: zenhive/mpp can pay unlimited gas fees

CVE-2026-59695 · published 14 days ago
Summary

The mpp library version 0.4.0 does not check the maximum gas price or fee limits before it signs a client transaction. A malicious client can set extremely high values, causing the server to pay those fees from its own wallet and potentially drain its funds. Upgrade to a version that validates fee limits or add custom checks to enforce reasonable caps and monitor wallet balances.

What to do
  • Update mpp to version 0.6.0.
Affected software
Ecosystem VendorProductAffected versions
– zenhive mpp < 0.6.0
< 5d6338e2334084c5f2a78cfcca474830733ed7e8
Hex – mpp >= 0.2.0, < 0.6.0
Fix: upgrade to 0.6.0
Original advisory text
mpp vulnerable to Gas Draining with no limit
### Details
When the server acts as the fee_payer, the `mpp` Elixir 0.4.0 does not validate `gas_limit`, `max_fee_per_gas` and `max_priority_fee_per_gas` before cosigning the client's fee-payer transaction. A malicious client embeds arbitrarily large `max_fee_per_gas` and `max_priority_fee_per_gas` values in the signed envelope. The server cosigns and broadcasts — paying those inflated gas costs from its own wallet based on the `effective_gas_price` calculated from the high `max_fee_per_gas` and `max_priority_fee_per_gas` set by the client.

**Vulnerable function:** `cosign_fee_payer/3` in [`transaction.ex`](https://hex.pm/packages/mpp/0.4.0) around lines 229–262.

### PoC
The PoC is provided below. It is configured to reproduce the attack on Tempo Moderate testnet within a Docker environment. Download the PoC and run:
```bash
unzip mpp_elixir_PoC.zip
cd mpp_elixir
docker build -t mpp-elixir-gasdrain .
docker run --rm mpp-elixir-gasdrain
```
There are more details in `mpp_elixir/README.md`

### Impact
By draining the server's wallet, an attacker causes direct financial loss to the organization. Furthermore, if the server's funds are drained completely, legitimate clients will have their requests fail, as the server can no longer fund future transactions, effectively creating a Denial of Service (DoS) attack.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-1284Improper Validation of Specified Quantity in Input
CWE-20Improper Input Validation
Timeline
Published25 Sep 2026
Updated9 Oct 2026
First seen17 Jul 2026
Sources
CVE-2026-59695 · MITRE
Track software like this
Free during beta