CVE-2026-63628
- EPSS 0.38%
- Veröffentlicht 22.09.2026 19:09:38
- Zuletzt bearbeitet 24.09.2026 15:17:26
mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, the fee-payer cosigning path in src/tempo/internal/fee-payer.ts copied a client-supplied access_list from a 0x78 FeePayerEnvelope without validating its length or contents....
CVE-2026-63627
- EPSS 0.38%
- Veröffentlicht 22.09.2026 19:07:02
- Zuletzt bearbeitet 23.09.2026 18:12:04
mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, FeePayerPolicy in src/tempo/internal/fee-payer.ts used decodeFunctionData to validate fee-sponsored calldata but did not reject trailing bytes. A client could append nonzer...
CVE-2026-34209
- EPSS 0.36%
- Veröffentlicht 31.03.2026 14:10:46
- Zuletzt bearbeitet 24.07.2026 21:10:00
mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the tempo/session cooperative close handler validated the close voucher amount using "<" instead of "<=" against the on-chain settled amount. An attacker could sub...
CVE-2026-34210
- EPSS 0.49%
- Veröffentlicht 31.03.2026 14:10:10
- Zuletzt bearbeitet 24.07.2026 21:10:00
mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method did not check Stripe's Idempotent-Replayed response header when creating PaymentIntents. An attacker could replay a valid credenti...