GHSA-vj8p-hp9x-gh47

Suggest an improvement
Source
https://github.com/advisories/GHSA-vj8p-hp9x-gh47
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-vj8p-hp9x-gh47/GHSA-vj8p-hp9x-gh47.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-vj8p-hp9x-gh47
Aliases
Published
2026-09-25T21:47:36Z
Modified
2026-09-25T23:00:30Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
mpp vulnerable to Gas Draining with low gas limit
Details

Vulnerability

When the server acts as the fee payer, mpp Elixir 0.4.0 (ZenHive/mpp) does not validate whether the gas_limit set by the client is enough before broadcasting. A malicious client can drain the server's gas without paying.

A transferWithMemo call on Tempo Moderato testnet requires ~51,299 gas to complete successfully. By setting gas_limit = 51,298:

  1. The Tx gets cosigned and broadcast by the server.
  2. The Tx runs out of gas during EVM execution. All state reverts.
  3. The server's fee-payer wallet is charged for gas used.
  4. The client pays nothing and receives no resource.
# Run the PoC
unzip mpp_elixir_low_gas_PoC.zip
cd mpp_elixir_low_gas_PoC
docker build -t mpp-elixir-low-gas .
docker run --rm mpp-elixir-low-gas

Zero-Cost DoS Attack: Unlike gas draining with access list or padding, where the malicious client needs to complete a payment to drain the gas, this vulnerability allows malicious users to continuously drain the server's gas at virtually no financial cost (requiring only computing power). Therefore, an attacker can spawn N malicious clients to completely drain the funds from the server's wallet to perform a Denial of Service (DoS) attack. Once the server's wallet is empty, it has no more funds to pay the gas fees for upcoming requests from legitimate clients.

# Run the DoS PoC
unzip mpp_elixir_low_gas_dos_PoC.zip
cd mpp_elixir_low_gas_dos_PoC
docker build -t mpp-elixir-dos .
docker run --rm mpp-elixir-dos

Vulnerable code path: broadcast_and_verify/7 in mpp/methods/tempo.ex (ZenHive/mpp 0.4.0). When wait_for_confirmation = true (the default), it calls rpc_broadcast_sync directly without any gas-adequacy check or simulation. The alternative wait_for_confirmation = false path does call simulate_payment_call via eth_call, but that simulation omits the gas parameter and therefore does not catch out-of-gas conditions.

Impact

A malicious client can drain the server's wallet without any financial cost.

Database specific
{
    "cwe_ids": [
        "CWE-20"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-25T21:47:36Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

Hex / mpp

Package

Name
mpp
Purl
pkg:hex/mpp

Affected ranges

Type
SEMVER
Events
Introduced
0.2.0
Fixed
0.6.0

Affected versions

0.*
0.2.0
0.3.0
0.3.1
0.3.2
0.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-vj8p-hp9x-gh47/GHSA-vj8p-hp9x-gh47.json"