Junglewise Threat Intelligence

CVE-2026-89186: ZenHive mpp HTTP cache header override vulnerability

CVE-2026-89186 · Severity: info · CVSS 0 · Published 2026-09-16

Technologies: ZenHive Mpp. Vendors: ZenHive.

Executive brief

ZenHive mpp is a payment authorization library that protects premium content by setting cache headers to prevent caching of paid resources. However, downstream applications can override these headers, allowing shared HTTP caches (CDNs, reverse proxies) to store paid responses and serve them to unpaid clients without payment verification. This undermines the core payment protection mechanism and allows free access to premium content.

Technical details

The vulnerability exists in MPP.Plug.verify_credential (lib/mpp/plug.ex), which sets cache-control: private to prevent caching of paid responses. However, the library fails to register a register_before_send/2 callback, allowing downstream applications to silently override the cache-control header using Plug.Conn.put_resp_header/3. An attacker (or misconfigured application) can set cache-control: public with a long max-age, allowing CDNs and reverse proxies to cache the paid response along with its Payment-Receipt and serve both to unauthenticated clients. Additionally, non-2xx responses incorrectly retain the Payment-Receipt header, issuing false payment receipts. Attack requires network access to the application and ability to control downstream caching behavior or exploit misconfigured headers. The vulnerability affects mpp versions 0.1.0 through 0.16.1; version 0.16.2+ contains the fix.

Affected products

  • ZenHive mpp 0.1.0 to 0.16.1

Timeline

  • 2026-09-16: disclosed: CVE-2026-89186 published
  • 2026-09-16: patched: Fix available in version 0.16.2

References

Related threats