DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-VJ8P-HP9X-GH47: GHSA-vj8p-hp9x-gh47: Zero-Cost Fee-Payer Wallet Gas Draining in mpp Elixir Library

GHSA-vj8p-hp9x-gh47: Zero-Cost Fee-Payer Wallet Gas Draining in mpp Elixir Library

Vulnerability ID: GHSA-VJ8P-HP9X-GH47
CVSS Score: 8.8
Published: 2026-09-25

A high-severity vulnerability exists in the Elixir library mpp (Multi-Party Payments) prior to version 0.6.0. When acting as a sponsored transaction fee payer, the server co-signs and broadcasts user-provided transactions without verifying if the user-specified gas limit is sufficient. An attacker can submit transactions designed to run out of gas and revert. The transaction reversion ensures the attacker pays zero fees, while the sponsor's fee-payer wallet is fully billed for the wasted gas, resulting in a low-cost, high-impact Denial of Service (DoS) vector.

TL;DR

An unauthenticated attacker can submit transaction payloads with insufficient gas limits to the mpp fee-payer endpoint. This forces the sponsor's wallet to pay for failed execution costs while the attacker incurs zero financial cost, draining the host's wallet and causing a denial of service.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-20
  • Attack Vector: Network
  • CVSS Score: 8.8
  • Impact: Denial of Service (DoS) via Wallet Exhaustion
  • Exploit Status: Proof-of-Concept (PoC) Available
  • KEV Status: Not Listed

Affected Systems

  • mpp Elixir library deployments configured as transaction fee-payer / sponsors
  • EVM-compatible Multi-Party Payment systems running on Tempo or related Account Abstraction protocols
  • mpp: >= 0.2.0, < 0.6.0 (Fixed in: 0.6.0)

Code Analysis

Commit: d84e3e5

Implement eth_simulateV1 pre-broadcast simulation on both synchronous and optimistic transaction pathways to protect sponsors against gas-draining attacks.

Exploit Details

  • GitHub Security Advisory Page: Exploit blueprint detailing setup instructions for single-transaction and multi-transaction DoS scenarios using Docker.

Mitigation Strategies

  • Upgrade the mpp package to version 0.6.0 or higher.
  • Ensure the connected JSON-RPC node supports the eth_simulateV1 endpoint.
  • Deploy rate-limiting at the API gateway layer to block rapid transaction submissions from individual clients.
  • Monitor fee-payer wallet balances and alert on unexpected revert rates.

Remediation Steps:

  1. Open the mix.exs file in your Elixir project.
  2. Locate the :mpp dependency and update the version constraints to '~> 0.6.0'.
  3. Run 'mix deps.update mpp' to update dependencies and rewrite mix.lock.
  4. Verify the application logs to ensure no 'eth_simulateV1 unsupported' warnings are generated when submitting transactions.

References


Read the full report for GHSA-VJ8P-HP9X-GH47 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)