7.1 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free
Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3 in lib/mpp/session/actions.ex treats a voucher whose cumulativeAmount equals the channel's already-accepted cumulative amount as an idempotent success, returning the channel unchanged without calling maybe_spend/2. The credential verifies, the protected resource is served, and spent and units stay where they were. Because the server issues a fresh challenge per request and the credential replay store keys on challenge id and payload, the same signed voucher can be re-presented under every new challenge, so one paid voucher yields an unbounded number of paid units. The path is reachable from any method built on MPP.Session.Method through the Plug, MCP, JSON-RPC and WebSocket transports. This issue affects mpp: from 0.14.0 before 0.16.2.
References
-
-
OSV record EEF-CVE-2026-89420 related
Affected products
- <0.16.2
- <7270edc1dcfb58250cc5ee812876609206564165
Matching in nixpkgs
pkgs.bumpp
Interactive CLI that bumps your version numbers and more
pkgs.qxmpp
Cross-platform C++ XMPP client and server library
pkgs.xmppc
Command Line Interface Tool for XMPP
pkgs.jumppad
Tool for building modern cloud native development environments
pkgs.igmpproxy
Daemon that routes multicast using IGMP forwarding
pkgs.go-sendxmpp
Tool to send messages or files to an XMPP contact or MUC
pkgs.xmpp-bridge
None
-
nixos-26.05 -
- nixos-26.05-small 0.6.0
pkgs.prometheus-xmpp-alerts
XMPP Web hook for Prometheus
pkgs.python313Packages.nbxmpp
Non-blocking Jabber/XMPP module
pkgs.python313Packages.xmpppy
Python 2/3 implementation of XMPP
pkgs.python314Packages.nbxmpp
Non-blocking Jabber/XMPP module
pkgs.python314Packages.xmpppy
Python 2/3 implementation of XMPP
pkgs.haskellPackages.hsendxmpp
sendxmpp clone, sending XMPP messages via CLI
pkgs.python313Packages.aioxmpp
None
-
nixos-26.05 -
- nixos-26.05-small 0.13.3
pkgs.python313Packages.slixmpp
Python library for XMPP
pkgs.python313Packages.smpplib
SMPP library for Python
pkgs.python314Packages.aioxmpp
None
-
nixos-26.05 -
- nixos-26.05-small 0.13.3
pkgs.python314Packages.slixmpp
Python library for XMPP
pkgs.python314Packages.smpplib
SMPP library for Python
pkgs.python313Packages.smpp-pdu
Library for parsing Protocol Data Units (PDUs) in SMPP protocol
-
nixos-unstable -
- nixos-unstable-small 0.3-unstable-2022-09-01
-
nixos-26.05 -
- nixos-26.05-small 0.3-unstable-2022-09-01
pkgs.python314Packages.smpp-pdu
Library for parsing Protocol Data Units (PDUs) in SMPP protocol
-
nixos-unstable -
- nixos-unstable-small 0.3-unstable-2022-09-01
-
nixos-26.05 -
- nixos-26.05-small 0.3-unstable-2022-09-01
pkgs.python313Packages.sleekxmppfs
Fork of SleekXMPP with TLS cert validation disabled, intended only to be used with the sucks project
pkgs.python314Packages.sleekxmppfs
Fork of SleekXMPP with TLS cert validation disabled, intended only to be used with the sucks project
pkgs.haskellPackages.pontarius-xmpp
An XMPP client library
pkgs.python313Packages.slixmpp-omemo
Slixmpp plugin for the Multi-End Message and Object Encryption protocol
pkgs.python314Packages.slixmpp-omemo
Slixmpp plugin for the Multi-End Message and Object Encryption protocol
pkgs.pidginPackages.pidgin-xmpp-receipts
Message delivery receipts (XEP-0184) Pidgin plugin
pkgs.haskellPackages.pontarius-xmpp-extras
XEPs implementation on top of pontarius-xmpp
pkgs.pidginPackages.purple-xmpp-http-upload
None
-
nixos-26.05 -
- nixos-26.05-small 2021-11-04
Package maintainers
-
@xiaoxiangmoe ZHAO JinXiang <xiaoxiangmoe@gmail.com>
-
@jpds Jonathan Davies
-
@sdier Scott Dier <scott@dier.name>
-
@cpcloud Phillip Cloud
-
@fpletz Franz Pletz <fpletz@fnordicwalking.de>
-
@haansn08 Stefan Haan
-
@dotlambda ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86 <nix@dotlambda.de>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@marijanp Marijan Petričević <marijan.petricevic94@gmail.com>
-
@flokli Florian Klink <flokli@flokli.de>
-
@jopejoe1 jopejoe1 <nixpkgs@missing.ninja>
-
@astro Astro <astro@spaceboyz.net>