CVE-2026-59695 Details
Description
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price. When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3 re-signs the client-supplied base fields of the 0x76 AASigned envelope verbatim, including max_fee_per_gas and max_priority_fee_per_gas, without validating that they are within reasonable bounds. A malicious client embeds arbitrarily large values for these fields in the signed envelope. The server co-signs and broadcasts the transaction. The effective_gas_price billed against the fee-payer wallet is derived from the attacker-supplied ceilings, so the server pays those inflated per-gas rates out of its own wallet. A single crafted request can drain the wallet entirely, after which the server can no longer sponsor gas for legitimate payment requests. This issue affects mpp: from 0.2.0 before 0.6.0.
A vulnerability in the ZenHive mpp Elixir library, specifically in versions 0.2.0 prior to 0.6.0, allows an unauthenticated remote client to drain the fee-payer wallet in a single request. This is achieved by embedding excessively high gas price values in the transaction envelope, which the server then co-signs and broadcasts. The inflated gas costs are deducted from the server's wallet, leading to a complete drain of funds. This issue arises because the library fails to properly validate client-supplied gas economics before processing fee-payer transactions, leaving the server vulnerable to exploitation.
Users can update to ZenHive mpp version 0.6.0 or later, where this vulnerability has been addressed. Instructions for updating can be found on the ZenHive mpp GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 17, 2026CISA-ADP
Assessed Jul 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ZenHive/mpp/security/advisories/GHSA-vv77-66rf-pm86 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://cna.erlef.org/cves/CVE-2026-59695.html | EEF | AdvisoryBundle |
| https://github.com/ZenHive/mpp/commit/5d6338e2334084c5f2a78cfcca474830733ed7e8 | EEF | Source CodeVendor |
| https://github.com/ZenHive/mpp/security/advisories/GHSA-vv77-66rf-pm86 | EEF | AdvisoryExploitRemedyVendor |
| https://osv.dev/vulnerability/EEF-CVE-2026-59695 | EEF | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1284 | Improper Validation of Specified Quantity in Input | EEF |
Affected Products
| Product | Versions |
|---|---|
| ZenHive mpp | >= 0.2.0, < 0.6.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 17, 2026 | CVE Modified | CISA-ADP |
| Jul 17, 2026 | New CVE Received | EEF |
Volerion