CVE-2026-82750 - Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation
Brief
CVE ID : CVE-2026-82750
Published : Sept. 6, 2026, 5:17 p. m.
- 3 hours, 31 minutes ago
Description : Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing.
When the server sponsors Tempo payments, MPP. Methods. Tempo. FeePayerPolicy. measure/3 in lib/mpp/methods/tempo/fee_payer_policy. ex bounds the gas fields, the fee budget, the validity window and the access list of the client-signed 0x76 envelope, but never reads its aa_authorization_list field.
