Zenhive

Machine Payments Protocol

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.5%
  • Veröffentlicht 19.08.2026 17:20:09
  • Zuletzt bearbeitet 10.09.2026 18:00:52

Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matches a trans...

  • EPSS 0.42%
  • Veröffentlicht 19.08.2026 17:20:00
  • Zuletzt bearbeitet 10.09.2026 18:24:36

Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.Methods.Tempo...

  • EPSS 0.54%
  • Veröffentlicht 19.08.2026 17:19:52
  • Zuletzt bearbeitet 10.09.2026 18:17:22

Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by replaying a transfer settled by an unrelated payer. MPP.Methods.Tempo normally binds a settled TIP-20 TransferWithMemo to the sp...

  • EPSS 0.24%
  • Veröffentlicht 19.08.2026 17:19:43
  • Zuletzt bearbeitet 10.09.2026 18:30:09

Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses. The type="hash" credential path in MPP.Methods.Tempo.verify/2 guar...