Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.6 Node.js & npm GHSA-727h-3vm5-qwq6 CVE-2026-63627 GHSA-vc9j-9wph-qghj CVE-2026-63628

mppx Fee-Payer Validation Flaws Allow Gas Fee Draining (CVE-2026-63628, CVE-2026-63627)

Two input validation flaws in mppx, a TypeScript interface for the machine payments protocol, let clients inflate gas fees charged to a server-side fee-payer wallet. Both are fixed in version 0.8.2.

AI summary

Two vulnerabilities have been disclosed in mppx, a TypeScript interface for the machine payments protocol, both affecting the fee-payer cosigning logic used to sponsor transaction fees on behalf of clients. The flaws allow a client to manipulate input data in ways that cause the server-operated fee-payer wallet to pay more in gas fees than intended, without breaching the gas or size limits normally enforced by policy. Both issues are fixed in mppx version 0.8.2.

What happened

Two separate but related CVEs were published for mppx. CVE-2026-63628 describes a flaw in the fee-payer cosigning path (src/tempo/internal/fee-payer.ts) where a client-supplied access_list from a FeePayerEnvelope was copied without validating its length or contents. In a demonstrated case, a 180-entry fabricated access list stayed within the 500,000 gas policy cap, the 16 KB header limit, and the RPC simulation budget, while increasing the fee paid by the server approximately 9.4 times. CVE-2026-63627 describes a related flaw in FeePayerPolicy, also in fee-payer.ts, where decodeFunctionData was used to validate fee-sponsored calldata but did not reject trailing bytes. A client could append nonzero padding that increased intrinsic calldata gas while gas_limit and max_fee_per_gas stayed within policy caps; the 16 KB header limit bounded the demonstrated padding to about 5,500 bytes and produced approximately five times the normal transaction fee.

Technical cause

Both issues stem from improper input validation (CWE-20) in the fee-payer cosigning logic of mppx. In CVE-2026-63628, the access_list field from a client-supplied FeePayerEnvelope was accepted and copied without checking its length or contents, allowing address-only entries that consume intrinsic EIP-2930 gas even though the listed addresses are never used. In CVE-2026-63627, FeePayerPolicy decoded fee-sponsored calldata using decodeFunctionData but failed to reject trailing bytes appended after the valid encoded data, allowing extra calldata gas to be charged without exceeding the configured gas_limit or max_fee_per_gas caps.

Why it matters

In both cases, the server-operated fee-payer wallet ends up paying substantially more in transaction fees than the sponsored transaction actually requires, while staying under the configured policy limits (gas cap, header size, and simulation budget) that were meant to bound sponsor costs. This creates a financial drain mechanism: a client can repeatedly submit crafted requests to inflate the fees paid by the fee-payer wallet without triggering the existing safeguards.

Who is affected

Any deployment of mppx that operates a server-side fee-payer wallet to cosign and sponsor transaction fees for clients, using versions prior to 0.8.2, is affected by both issues.

Affected versions

CVE-2026-63628 affects mppx versions from 0 up to but not including 0.8.2. CVE-2026-63627 affects mppx versions from 0 up to but not including 0.8.1. Both issues are fixed in version 0.8.2.

Fixes and mitigation

Both vulnerabilities are fixed in mppx version 0.8.2. The fact package does not specify the exact code changes made in the fix beyond resolving the described validation gaps.

Recommended action

Operators running mppx with a server-side fee-payer wallet should upgrade to version 0.8.2 as soon as practical. There is no indication in the available facts of a viable workaround short of upgrading.

PatchBriefing score

4.6 / 10 · Medium

Official CVSS: 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

Both CVE-2026-63628 and CVE-2026-63627 carry a CVSS 4.0 base score of 6.9 and a PatchBriefing score of 4.6. The score reflects that the flaws are exploitable remotely without authentication or user interaction (contributing factors: unauthenticated_remote and no_user_interaction), while availability impact is limited to financial/resource drain on the fee-payer wallet rather than confidentiality or integrity loss. No known exploitation in the wild, no public exploit code, and no EPSS data are recorded for either issue. A fix is available for both, which is reflected in the scoring.

Affected versions

mppx < 0.8.1
vulnerable
≥ 0.8.2
patched
mppx < 0.8.2
vulnerable
≥ 0.8.2
patched

Reported fixes

Both vulnerabilities are fixed in mppx version 0.8.2. The fact package does not specify the exact code changes made in the fix beyond resolving the described validation gaps.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • GitHub Advisory Database database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
mppx Fee-Payer Validation Flaws Allow Gas Fee Draining (CVE-2026-63628, CVE-2026-63627)
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email