Denial of Service Vulnerability in ZenHive mpp Affects Unauthenticated Clients
CVE-2026-73541

8.3HIGH

Key Information:

Vendor

Zenhive

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-73541?

A vulnerability in ZenHive's mpp allows unauthenticated remote clients to exploit the system by executing multiple concurrent sponsored payments, which can drain the fee-payer wallet completely. Once the wallet is emptied, legitimate payers are denied service, as the policy enforcing transaction ceilings only applies to individual requests. This design oversight means that simultaneous transactions are not limited by a global cap, thus leading to potential financial loss and service disruption.

Affected Version(s)

mpp 0.2.0 < 0.12.0

mpp d29d54e507918db00a5b65d90136b73166c017d7

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

E.FU
E.FU
Jonatan Männchen / EEF
.