VYPR
Vendor

ZenHive

Products
3
CVEs
11
Across products
14
Status
Private

Products

3

Recent CVEs

11
  • CVE-2026-82751HigSep 6, 2026
    risk 0.47cvss epss 0.00

    Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account. When…

  • CVE-2026-82750HigSep 6, 2026
    risk 0.47cvss epss 0.00

    Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing. When…

  • CVE-2026-73541HigAug 19, 2026
    risk 0.46cvss 8.2epss 0.00

    Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.Methods.Tempo.FeePayerPolicy enforces its…

  • CVE-2026-73136HigAug 19, 2026
    risk 0.42cvss 7.5epss 0.00

    Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by replaying a transfer settled by an unrelated payer. MPP.Methods.Tempo normally binds a settled TIP-20 TransferWithMemo to the specific challenge under…

  • CVE-2026-67581HigAug 19, 2026
    risk 0.42cvss 7.5epss 0.00

    Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matches a transfer purely on token, to and…

  • CVE-2026-89186MedSep 16, 2026
    risk 0.34cvss epss 0.00

    Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients that never paid. MPP.Plug.verify_credential in lib/mpp/plug.ex sets payment-receipt and cache-control: private on the connection before the…

  • CVE-2026-88255MedSep 16, 2026
    risk 0.34cvss epss 0.00

    Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Tempo duplicate-submission gate twice with one signed transaction. MPP.Methods.Tempo reserves the pre-broadcast dedup slot on the caller-supplied hex in…

  • CVE-2026-73829LowAug 19, 2026
    risk 0.17cvss 3.7epss 0.00

    Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses. The type="hash" credential path in MPP.Methods.Tempo.verify/2 guards against replay with a…

  • CVE-2026-59695HigJul 17, 2026
    risk 0.00cvss epss 0.01

    Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price. When the mpp Elixir library is configured as fee payer (fee_payer: true),…

  • CVE-2026-59694HigJul 17, 2026
    risk 0.00cvss epss 0.01

    Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multiplier, degrading the sponsor's operating margin. When the mpp Elixir library is configured as fee payer…

  • CVE-2026-59252HigJul 17, 2026
    risk 0.00cvss epss 0.01

    Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitimate clients. When the mpp Elixir library is configured as fee payer (fee_payer: true), the…