Vulnerabilidades em ZenHive
9 resultadosAnálise Vexday
ZenHive apresenta uma base modesta de três vulnerabilidades, todas publicadas recentemente (últimos 90 dias), sem ataque ativo confirmado ou severidade crítica. A fraqueza dominante (CWE-1284, relacionada a propriedades de segurança inadequadas) sugere problemas arquiteturais que merecem atenção proativa, especialmente considerando o ciclo recente de divulgações.
CVE-2026-59252HIGHMissing gas_limit validation in mpp Tempo fee-payer enables wallet drainEPSS 0.6%CVE-2026-73136HIGHStatic memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replayEPSS 0.5%CVE-2026-59695HIGHUnbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drainEPSS 0.5%CVE-2026-59694HIGHUnbounded access list in mpp Tempo fee-payer inflates gas cost per paymentEPSS 0.5%CVE-2026-67581HIGHOn-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replayEPSS 0.5%CVE-2026-73541HIGHTempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drainEPSS 0.4%CVE-2026-82750HIGHUnbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegationEPSS 0.3%CVE-2026-82751HIGHUnbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioningEPSS 0.3%CVE-2026-73829MEDIUMNon-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent raceEPSS 0.2%