« Volver al listado

Zenhive

Zenhive MPP: vulnerabilidades y CVE

Zenhive MPP tiene 9 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses9
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-89420Alta (7.1)0.41%—22 sept 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3 in…
CVE-2026-87119Alta (8.2)0.57%—22 sept 2026
Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id,…
CVE-2026-89186Media (6.3)0.52%—16 sept 2026
Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients that never paid. MPP.Plug.verify_credential in lib/mpp/plug.ex sets…
CVE-2026-88255Media (6.3)0.52%—16 sept 2026
Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Tempo duplicate-submission gate twice with one signed transaction. MPP.Methods.Tempo reserves the…
CVE-2026-82751Alta (8.3)0.52%—6 sept 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for…
CVE-2026-82750Alta (8.3)0.52%—6 sept 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for…
CVE-2026-59695Alta (8.3)0.52%—17 jul 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price. When the mpp Elixir…
CVE-2026-59694Alta (8.3)0.52%—17 jul 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multiplier, degrading the sponsor's operating margin.…
CVE-2026-59252Alta (8.2)0.63%—17 jul 2026
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitimate clients. When the mpp Elixir library…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application6
  2. T1499.004 Application or System Exploitation5
  3. T1021 Remote Services1
  4. T1210 Exploitation of Remote Services1
  5. T1578 Modify Cloud Compute Infrastructure1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Zenhive