← All credits
E.FU
13 vulnerability records and advisories credit this contributor.
CVE-2026-89420
Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free
CVE-2026-87119
mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed
CVE-2026-89186
mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches
CVE-2026-88255
mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot
CVE-2026-73829
Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race
CVE-2026-73541
Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain
CVE-2026-73136
Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay
CVE-2026-67581
On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay
CVE-2026-82751
Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning
CVE-2026-82750
Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation