<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 14:47:22 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-338649</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338649</link>
      <description>EUVD-2026-338649</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338649</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59694</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59694</link>
      <description>&lt;p&gt;Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer&amp;#39;s gas cost per payment by a large multiplier, degrading the sponsor&amp;#39;s operating margin.&lt;/p&gt;
&lt;p&gt;When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3 re-signs the client-supplied base fields of the 0x76 AASigned envelope verbatim, including the EIP-2930 access list, without validating its length or contents. EIP-2930 access list entries incur intrinsic gas (~2,400 gas per address, plus 1,900 gas per storage key) charged before any opcode executes, regardless of whether the listed addresses are ever touched. A malicious client submits a valid transferWithMemo call alongside a large number of fabricated access-list entries. The server co-signs and broadcasts the transaction. The intended transfer executes normally, but the fee-payer wallet pays a large multiple of the expected gas cost with no corresponding on-chain work.&lt;/p&gt;
&lt;p&gt;At the maintainer&amp;#39;s default of 137 access-list entries (fitting within Bandit&amp;#39;s 10,000-byte per-header-field limit) and 100 Gwei max_fee_per_gas, per-payment gas cost rises from ~51,287 to ~380,087 gas, a 7.4x multiplier. Sustained abuse destroys the sponsor&amp;#39;s operating margin on low-cost payments and, over time, drains the fee-payer wallet.&lt;/p&gt;
&lt;p&gt;This issue affects mpp: from 0.2.0 before 0.6.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer&amp;#39;s gas cost per payment by a large multiplier, degrading the sponsor&amp;#39;s operating margin.&lt;/p&gt;
&lt;p&gt;When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3 re-signs the client-supplied base fields of the 0x76 AASigned envelope verbatim, including the EIP-2930 access list, without validating its length or contents. EIP-2930 access list entries incur intrinsic gas (~2,400 gas per address, plus 1,900 gas per storage key) charged before any opcode executes, regardless of whether the listed addresses are ever touched. A malicious client submits a valid transferWithMemo call alongside a large number of fabricated access-list entries. The server co-signs and broadcasts the transaction. The intended transfer executes normally, but the fee-payer wallet pays a large multiple of the expected gas cost with no corresponding on-chain work.&lt;/p&gt;
&lt;p&gt;At the maintainer&amp;#39;s default of 137 access-list entries (fitting within Bandit&amp;#39;s 10,000-byte per-header-field limit) and 100 Gwei max_fee_per_gas, per-payment gas cost rises from ~51,287 to ~380,087 gas, a 7.4x multiplier. Sustained abuse destroys the sponsor&amp;#39;s operating margin on low-cost payments and, over time, drains the fee-payer wallet.&lt;/p&gt;
&lt;p&gt;This issue affects mpp: from 0.2.0 before 0.6.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59694</guid>
    </item>
    <item>
      <title>GHSA-r4hx-mhrp-xf73</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r4hx-mhrp-xf73</link>
      <description>&lt;p&gt;Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer&amp;#39;s gas cost per payment by a large multiplier, degrading the sponsor&amp;#39;s operating margin.&lt;/p&gt;
&lt;p&gt;When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3 re-signs the client-supplied base fields of the 0x76 AASigned envelope verbatim, including the EIP-2930 access list, without validating its length or contents. EIP-2930 access list entries incur intrinsic gas (~2,400 gas per address, plus 1,900 gas per storage key) charged before any opcode executes, regardless of whether the listed addresses are ever touched. A malicious client submits a valid transferWithMemo call alongside a large number of fabricated access-list entries. The server co-signs and broadcasts the transaction. The intended transfer executes normally, but the fee-payer wallet pays a large multiple of the expected gas cost with no corresponding on-chain work.&lt;/p&gt;
&lt;p&gt;At the maintainer&amp;#39;s default of 137 access-list entries (fitting within Bandit&amp;#39;s 10,000-byte per-header-field limit) and 100 Gwei max_fee_per_gas, per-payment gas cost rises from ~51,287 to ~380,087 gas, a 7.4x multiplier. Sustained abuse destroys the sponsor&amp;#39;s operating margin on low-cost payments and, over time, drains the fee-payer wallet.&lt;/p&gt;
&lt;p&gt;This issue affects mpp: from 0.2.0 before 0.6.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer&amp;#39;s gas cost per payment by a large multiplier, degrading the sponsor&amp;#39;s operating margin.&lt;/p&gt;
&lt;p&gt;When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3 re-signs the client-supplied base fields of the 0x76 AASigned envelope verbatim, including the EIP-2930 access list, without validating its length or contents. EIP-2930 access list entries incur intrinsic gas (~2,400 gas per address, plus 1,900 gas per storage key) charged before any opcode executes, regardless of whether the listed addresses are ever touched. A malicious client submits a valid transferWithMemo call alongside a large number of fabricated access-list entries. The server co-signs and broadcasts the transaction. The intended transfer executes normally, but the fee-payer wallet pays a large multiple of the expected gas cost with no corresponding on-chain work.&lt;/p&gt;
&lt;p&gt;At the maintainer&amp;#39;s default of 137 access-list entries (fitting within Bandit&amp;#39;s 10,000-byte per-header-field limit) and 100 Gwei max_fee_per_gas, per-payment gas cost rises from ~51,287 to ~380,087 gas, a 7.4x multiplier. Sustained abuse destroys the sponsor&amp;#39;s operating margin on low-cost payments and, over time, drains the fee-payer wallet.&lt;/p&gt;
&lt;p&gt;This issue affects mpp: from 0.2.0 before 0.6.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r4hx-mhrp-xf73</guid>
    </item>
  </channel>
</rss>
