Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

mpp — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in mpp, with AI-generated Chinese analysis, references, and POCs.

Vendor: ZenHive

CVE ID Title CVSS Severity Published
CVE-2026-87119 mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed CWE-294 8.2 High 2026-09-22
CVE-2026-89420 Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free CWE-1284 7.1 High 2026-09-22
CVE-2026-88255 mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot CWE-1289 6.3 Medium 2026-09-16
CVE-2026-89186 mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches CWE-524 6.3 Medium 2026-09-16
CVE-2026-82750 Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation CWE-1284 8.3 High 2026-09-06
CVE-2026-82751 Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning CWE-1284 8.3 High 2026-09-06
CVE-2026-67581 On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay CWE-294 8.7 High 2026-08-19
CVE-2026-73541 Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain CWE-770 8.3 High 2026-08-19
CVE-2026-73136 Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay CWE-294 8.2 High 2026-08-19
CVE-2026-73829 Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race CWE-367 6.3 Medium 2026-08-19
CVE-2026-59252 Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain CWE-1284 - - 2026-07-17
CVE-2026-59694 Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment CWE-1284 - - 2026-07-17
CVE-2026-59695 Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain CWE-1284 - - 2026-07-17

All 13 known CVE vulnerabilities affecting mpp with full Chinese analysis, references, and POCs where available.