Improper Input Validation in ZenHive mpp Affects Gas Cost Management
CVE-2026-82750
What is CVE-2026-82750?
The improper input validation in ZenHive's mpp allows unauthenticated remote clients to exploit fee-payer gas costs during sponsored payments. Through a vulnerability in the MPP.Methods.Tempo.FeePayerPolicy, clients can inflate the gas expenses significantly when delegating account control. The gas limit is breached by the inclusion of unauthorized delegations, leading to a dramatic increase in gas costs from approximately 46,575 to 1,884,087. This enables clients to make sponsors pay for actions they did not authorize, directly impacting the sponsor's financial liabilities during transaction processes.
Affected Version(s)
mpp 0.2.0 < 0.16.1
mpp d29d54e507918db00a5b65d90136b73166c017d7 < 0482572b47e1ffe1537ab80ab613d47b92833c2d
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
