Race Condition Vulnerability in ZenHive mpp Software
CVE-2026-73829
What is CVE-2026-73829?
A race condition vulnerability exists within the ZenHive mpp software, enabling unauthenticated remote clients to exploit a flaw in the payment redemption process. Specifically, concurrent requests can successfully redeem multiple resources for a single confirmed on-chain payment due to a non-atomic check-then-mark sequence. This flaw arises from the lack of an atomic check_and_mark mechanism for the type='hash' credential path, which, although secure in other paths, fails to protect against replay attacks in this scenario. Exploitation necessitates configuration of a deduplication store, as the default configuration does not provide any replay protection, making affected users at risk of unauthorized resource access.
Affected Version(s)
mpp 0.2.0 < 0.6.1
mpp f8904666061fbab695874856d8fcd02c471dfe1b < 46c5b0e1311da7d92190dc7d9ea89027a1d365e9
