{"id":"GHSA-vj8p-hp9x-gh47","summary":"mpp vulnerable to Gas Draining with low gas limit","details":"## Vulnerability\nWhen the server acts as the fee payer, `mpp` Elixir 0.4.0 (ZenHive/mpp) does not validate whether the `gas_limit` set by the client is enough before broadcasting. A malicious client can drain the server's gas without paying.\n\nA `transferWithMemo` call on Tempo Moderato testnet requires **~51,299 gas** to complete successfully. By setting `gas_limit = 51,298`:\n\n1. The Tx gets cosigned and broadcast by the server.\n2. The Tx runs out of gas during EVM execution. All state reverts.\n3. The server's fee-payer wallet is charged for gas used.\n4. The client pays nothing and receives no resource.\n\n```bash\n# Run the PoC\nunzip mpp_elixir_low_gas_PoC.zip\ncd mpp_elixir_low_gas_PoC\ndocker build -t mpp-elixir-low-gas .\ndocker run --rm mpp-elixir-low-gas\n```\n\n**Zero-Cost DoS Attack:** Unlike gas draining with `access list` or `padding`, where the malicious client needs to complete a payment to drain the gas, this vulnerability allows malicious users to continuously drain the server's gas at virtually no financial cost (requiring only computing power). Therefore, an attacker can spawn *N* malicious clients to completely drain the funds from the server's wallet to perform a Denial of Service (DoS) attack. Once the server's wallet is empty, it has no more funds to pay the gas fees for upcoming requests from legitimate clients. \n\n```bash\n# Run the DoS PoC\nunzip mpp_elixir_low_gas_dos_PoC.zip\ncd mpp_elixir_low_gas_dos_PoC\ndocker build -t mpp-elixir-dos .\ndocker run --rm mpp-elixir-dos\n```\n\n**Vulnerable code path:** `broadcast_and_verify/7` in `mpp/methods/tempo.ex` (ZenHive/mpp 0.4.0).\nWhen `wait_for_confirmation = true` (the default), it calls `rpc_broadcast_sync` directly without any gas-adequacy check or simulation. The alternative `wait_for_confirmation = false` path does call `simulate_payment_call` via `eth_call`, but that simulation omits the `gas` parameter and therefore does not catch out-of-gas conditions.\n\n## Impact\nA malicious client can drain the server's wallet without any financial cost.","aliases":["CVE-2026-59252","EEF-CVE-2026-59252"],"modified":"2026-09-25T23:00:30.229536889Z","published":"2026-09-25T21:47:36Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-09-25T21:47:36Z","nvd_published_at":null,"cwe_ids":["CWE-20"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/ZenHive/mpp/security/advisories/GHSA-vj8p-hp9x-gh47"},{"type":"WEB","url":"https://github.com/ZenHive/mpp/commit/d84e3e528db39654540c2035ea0fbdf7b950d3d1"},{"type":"PACKAGE","url":"https://github.com/ZenHive/mpp"},{"type":"WEB","url":"https://github.com/ZenHive/mpp/releases/tag/v0.6.0"}],"affected":[{"package":{"name":"mpp","ecosystem":"Hex","purl":"pkg:hex/mpp"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.2.0"},{"fixed":"0.6.0"}]}],"versions":["0.2.0","0.3.0","0.3.1","0.3.2","0.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-vj8p-hp9x-gh47/GHSA-vj8p-hp9x-gh47.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"}]}