8.2 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): Present (P)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): Present (P)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitimate clients. When the mpp Elixir library is configured as fee payer (fee_payer: true), the MPP.Methods.Tempo payment method co-signs and broadcasts a client-supplied EVM transaction without first validating that the client-supplied gas_limit is sufficient to complete the intended call. A malicious client can submit a signed transferWithMemo transaction with gas_limit deliberately set just below the amount required for successful execution. The server co-signs the transaction and broadcasts it via rpc_broadcast_sync. The transaction runs out of gas during EVM execution and reverts, but the fee-payer wallet is still charged for the burned gas while the client pays nothing and receives no resource. Repeated requests from one or more malicious clients drain the fee-payer wallet at near-zero cost to the attacker, ultimately preventing the server from sponsoring gas for legitimate payment requests. The wait_for_confirmation = false (optimistic) path is also affected: it invokes simulate_payment_call via eth_call, but that simulation omits the gas parameter and therefore does not catch out-of-gas conditions. This issue affects mpp: from 0.2.0 before 0.6.0.
References
Affected products
- <0.6.0
- <d84e3e528db39654540c2035ea0fbdf7b950d3d1
Matching in nixpkgs
pkgs.bumpp
Interactive CLI that bumps your version numbers and more
pkgs.qxmpp
Cross-platform C++ XMPP client and server library
pkgs.xmppc
Command Line Interface Tool for XMPP
pkgs.jumppad
Tool for building modern cloud native development environments
pkgs.igmpproxy
Daemon that routes multicast using IGMP forwarding
pkgs.go-sendxmpp
Tool to send messages or files to an XMPP contact or MUC
pkgs.xmpp-bridge
Connect command-line programs to XMPP
pkgs.prometheus-xmpp-alerts
XMPP Web hook for Prometheus
pkgs.python313Packages.nbxmpp
Non-blocking Jabber/XMPP module
pkgs.python313Packages.xmpppy
Python 2/3 implementation of XMPP
pkgs.python314Packages.nbxmpp
Non-blocking Jabber/XMPP module
pkgs.python314Packages.xmpppy
Python 2/3 implementation of XMPP
pkgs.haskellPackages.hsendxmpp
sendxmpp clone, sending XMPP messages via CLI
pkgs.python313Packages.aioxmpp
Pure-python XMPP library for asyncio
pkgs.python313Packages.slixmpp
Python library for XMPP
pkgs.python313Packages.smpplib
SMPP library for Python
pkgs.python314Packages.aioxmpp
Pure-python XMPP library for asyncio
pkgs.python314Packages.slixmpp
Python library for XMPP
pkgs.python314Packages.smpplib
SMPP library for Python
pkgs.python313Packages.smpp-pdu
Library for parsing Protocol Data Units (PDUs) in SMPP protocol
-
nixos-unstable 0.3-unstable-2022-09-01
- nixpkgs-unstable 0.3-unstable-2022-09-01
- nixos-unstable-small 0.3-unstable-2022-09-01
-
nixos-26.05 0.3-unstable-2022-09-01
- nixos-26.05-small 0.3-unstable-2022-09-01
- nixpkgs-26.05-darwin 0.3-unstable-2022-09-01
pkgs.python314Packages.smpp-pdu
Library for parsing Protocol Data Units (PDUs) in SMPP protocol
-
nixos-unstable 0.3-unstable-2022-09-01
- nixpkgs-unstable 0.3-unstable-2022-09-01
- nixos-unstable-small 0.3-unstable-2022-09-01
-
nixos-26.05 0.3-unstable-2022-09-01
- nixos-26.05-small 0.3-unstable-2022-09-01
- nixpkgs-26.05-darwin 0.3-unstable-2022-09-01
pkgs.python313Packages.sleekxmppfs
Fork of SleekXMPP with TLS cert validation disabled, intended only to be used with the sucks project
pkgs.python314Packages.sleekxmppfs
Fork of SleekXMPP with TLS cert validation disabled, intended only to be used with the sucks project
pkgs.haskellPackages.pontarius-xmpp
An XMPP client library
pkgs.python313Packages.slixmpp-omemo
Slixmpp plugin for the Multi-End Message and Object Encryption protocol
pkgs.python314Packages.slixmpp-omemo
Slixmpp plugin for the Multi-End Message and Object Encryption protocol
pkgs.pidginPackages.pidgin-xmpp-receipts
Message delivery receipts (XEP-0184) Pidgin plugin
pkgs.haskellPackages.pontarius-xmpp-extras
XEPs implementation on top of pontarius-xmpp
pkgs.pidginPackages.purple-xmpp-http-upload
HTTP File Upload plugin for libpurple (XMPP Protocol XEP-0363)
-
nixos-unstable 2021-11-04
- nixpkgs-unstable 2021-11-04
- nixos-unstable-small 2021-11-04
-
nixos-26.05 2021-11-04
- nixos-26.05-small 2021-11-04
- nixpkgs-26.05-darwin 2021-11-04
Package maintainers
-
@xiaoxiangmoe ZHAO JinXiang <xiaoxiangmoe@gmail.com>
-
@jpds Jonathan Davies
-
@sdier Scott Dier <scott@dier.name>
-
@cpcloud Phillip Cloud
-
@emmanuelrosa Emmanuel Rosa <emmanuelrosa@protonmail.com>
-
@fpletz Franz Pletz <fpletz@fnordicwalking.de>
-
@dotlambda ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86 <nix@dotlambda.de>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@marijanp Marijan Petričević <marijan.petricevic94@gmail.com>
-
@flokli Florian Klink <flokli@flokli.de>
-
@jopejoe1 jopejoe1 <nixpkgs@missing.ninja>
-
@astro Astro <astro@spaceboyz.net>
-
@Gigahawk jasperchan515@gmail.com <Jasper Chan>