ZenHive MPP是ZenHive组织开源的一款嵌入式服务器。 ZenHive MPP 0.3.0至0.6.3之前版本存在授权问题漏洞,该漏洞源于对交易哈希凭证的验证不充分,未将证明绑定到具体挑战或使用记录,可导致捕获重放身份验证绕过,使未经身份验证的远程客户端通过重放已结算的链上转账获取付费资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-73541 | 8.3 HIGH | Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing |
| CVE-2026-73136 | 8.2 HIGH | Static memo configuration in mpp Tempo disables per-challenge attribution binding, enablin |
| CVE-2026-73829 | 6.3 MEDIUM | Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a |
No comments yet