Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestion detail

Untriaged
Permalink CVE-2026-87119
8.2 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 days, 5 hours ago Activity log
  • Created suggestion
mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed

Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. MPP.Methods.Tempo.KeyAuthorization.verify/3 in lib/mpp/methods/tempo/key_authorization.ex pins each of those signed fields against the subscription request, and the access key it pins is a static per-endpoint server key, so one signed authorization verifies against every challenge the server issues for the same subscription terms. MPP.Methods.Tempo.Subscription.activate/4 deduplicates activations by challenge id, so presenting the captured credential under a fresh challenge produces a different dedup key, claim_activation succeeds, and the subscription transaction is built and broadcast again. Each replay charges the payer's wallet a new first-period settlement and re-authorizes the server key, bounded only by the subscription expiry and the chain's own semantics for re-installing an existing key. This issue affects mpp: from 0.14.0 before 0.16.2.

Affected products

mpp
  • <0.16.2
zenhive/mpp
  • <4b6eaec02af0e8485cfb4ff68f467d075ed5dd6f

Matching in nixpkgs

pkgs.bumpp

Interactive CLI that bumps your version numbers and more

  • nixos-unstable -
  • nixos-26.05 -

pkgs.qxmpp

Cross-platform C++ XMPP client and server library

  • nixos-unstable -
  • nixos-26.05 -

pkgs.xmppc

Command Line Interface Tool for XMPP

  • nixos-unstable -
    • nixos-unstable-small 0.1.2
  • nixos-26.05 -
    • nixos-26.05-small 0.1.2

pkgs.jumppad

Tool for building modern cloud native development environments

  • nixos-unstable -
  • nixos-26.05 -

pkgs.xmpp-dns

CLI tool to check XMPP SRV records

  • nixos-unstable -
    • nixos-unstable-small 0.6.4

pkgs.igmpproxy

Daemon that routes multicast using IGMP forwarding

  • nixos-unstable -
    • nixos-unstable-small 0.4
  • nixos-26.05 -
    • nixos-26.05-small 0.4

pkgs.go-sendxmpp

Tool to send messages or files to an XMPP contact or MUC

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python313Packages.sleekxmppfs

Fork of SleekXMPP with TLS cert validation disabled, intended only to be used with the sucks project

  • nixos-unstable -
    • nixos-unstable-small 1.4.1
  • nixos-26.05 -
    • nixos-26.05-small 1.4.1

pkgs.python314Packages.sleekxmppfs

Fork of SleekXMPP with TLS cert validation disabled, intended only to be used with the sucks project

  • nixos-unstable -
    • nixos-unstable-small 1.4.1
  • nixos-26.05 -
    • nixos-26.05-small 1.4.1

Package maintainers