CVE-2026-73541 — Zenhive Machine_payments_protocol: Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote
Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.Methods.Tempo.FeePayerPolicy enforces its ceilings (max_gas, max_fee_per_gas, max_priority_fee_per_gas, the worst-case gas_limit * max_fee_per_gas <= max_total_fee budget cap, and a validity window) against one transaction at a time, and nothi CVSSv3.1 8.2 (HIGH) · EPSS 35th percentile