{"id":"GHSA-fxc9-7j2w-vx54","aliases":[],"url":"https://o3.security/vulnerability/GHSA-fxc9-7j2w-vx54","summary":"mpp has multiple payment bypass and griefing vulnerabilities","details":"### Impact\nMultiple vulnerabilities were discovered which allowed for undesirable behaviors, including:\n- Performing free `tempo/charge` requests\n- Replaying existing `tempo/charge` requests\n- Performing free `tempo/session` requests\n- Piggybacking off existing `tempo/session` channels\n- Griefing existing `tempo/session` channels\n- Manipulate the fee payer of a `tempo/charge` or `tempo/session` handler into paying for requests\n- Replaying existing `stripe/charge` requests\n\n### Patches\nThe issues are patched in 0.8.0\n\n### Workarounds\nThere are no workarounds available for these vulnerabilities","published":"2026-03-29T15:20:45Z","modified":"2026-03-29T15:33:28.903431Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"mpp","fixedVersion":"0.8.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/tempoxyz/mpp-rs/security/advisories/GHSA-fxc9-7j2w-vx54"},{"type":"PACKAGE","url":"https://github.com/tempoxyz/mpp-rs"},{"type":"WEB","url":"https://github.com/tempoxyz/mpp-rs/releases/tag/v0.8.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-29T15:33:28.903431Z"}}