Denial of Service Vulnerability in ZenHive mpp Affects Unauthenticated Clients
CVE-2026-73541
8.3HIGH
What is CVE-2026-73541?
A vulnerability in ZenHive's mpp allows unauthenticated remote clients to exploit the system by executing multiple concurrent sponsored payments, which can drain the fee-payer wallet completely. Once the wallet is emptied, legitimate payers are denied service, as the policy enforcing transaction ceilings only applies to individual requests. This design oversight means that simultaneous transactions are not limited by a global cap, thus leading to potential financial loss and service disruption.
Affected Version(s)
mpp 0.2.0 < 0.12.0
mpp d29d54e507918db00a5b65d90136b73166c017d7
