Executive brief
ZenHive mpp is an Elixir library used for processing blockchain transactions. A vulnerability exists where the library fails to check the gas price requested by users when the server is configured to pay transaction fees. An attacker can send a single request with an extremely high gas price, causing the server to pay massive fees and potentially draining its entire digital wallet, which leads to financial loss and prevents legitimate users from making payments.
Technical details
The vulnerability is caused by improper validation of specified quantities (CWE-1284) in the MPP.Tempo.Transaction.cosign_fee_payer/3 function. When the library is configured with fee_payer: true, it re-signs client-supplied fields of the 0x76 AASigned envelope verbatim. An attacker can provide arbitrarily high values for max_fee_per_gas and max_priority_fee_per_gas, which the server then co-signs and broadcasts. This results in the server paying inflated per-gas rates from its own wallet. The issue is fixed in version 0.6.0.
Affected products
- ZenHive mpp from 0.2.0 before 0.6.0
Timeline
- 2026-06-24: advisory: Initial GitHub security advisory published
- 2026-07-17: disclosed: CVE-2026-59695 published to NVD