Improper Input Validation in ZenHive mpp Allows Unauthenticated Exploitation
CVE-2026-82751
What is CVE-2026-82751?
The ZenHive mpp product is vulnerable due to improper validation of specified input quantities, enabling unauthenticated remote clients to significantly inflate the gas costs billed to sponsors of payments. This occurs within the MPP.Methods.Tempo.FeePayerPolicy.measure/3 function, where bound gas fields and limits do not check the optional key_authorization field. This oversight allows clients to exploit the payment method by attaching a signed key authorization request, leading to large increases in sponsorship costs, as clients can provision access keys on their accounts without financial accountability. As the sponsored transactions scale, the gas usage can escalate drastically, raising legitimate concerns about cost management and resource allocation for the sponsors.
Affected Version(s)
mpp 0.2.0 < 0.16.1
mpp d29d54e507918db00a5b65d90136b73166c017d7 < 0482572b47e1ffe1537ab80ab613d47b92833c2d
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
