DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-QPXH-FF8M-C62V: GHSA-QPXH-FF8M-C62V: Gas Draining and Resource Exhaustion in ZenHive mpp Library

GHSA-QPXH-FF8M-C62V: Gas Draining and Resource Exhaustion in ZenHive mpp Library

Vulnerability ID: GHSA-QPXH-FF8M-C62V
CVSS Score: 7.5
Published: 2026-09-25

A critical gas draining vulnerability exists in the ZenHive mpp (Multi-Payment Protocol) library prior to version v0.6.0. By omitting validation of EIP-2930 access lists in custom 0x76 transaction envelopes, the library allows malicious clients to pad transaction payloads with dummy addresses, draining the gas sponsor's hot wallet.

TL;DR

Unvalidated access list padding allows attackers to drain native tokens from sponsored gas wallets on EVM-compatible networks.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400, CWE-20
  • Attack Vector: Network / Remote
  • CVSS Score: 7.5 (High)
  • Impact: Wallet Fund Depletion / Denial of Service
  • Exploit Status: Proof of Concept available

Affected Systems

  • ZenHive mpp (Multi-Payment Protocol) Elixir library
  • mpp: < 0.6.0 (Fixed in: 0.6.0)

Code Analysis

Commit: 5d6338e

Implement MPP.Methods.Tempo.FeePayerPolicy validation

Mitigation Strategies

  • Upgrade ZenHive mpp library to v0.6.0 or higher
  • Temporarily disable transaction fee sponsorship in application configuration

Remediation Steps:

  1. Update mix.exs with {:mpp, "~> 0.6.0"}
  2. Run mix deps.get and mix compile to pull the patched version
  3. Verify the fee payer policy config is enabled and active

References


Read the full report for GHSA-QPXH-FF8M-C62V on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)