{"id":"GHSA-727h-3vm5-qwq6","summary":"mppx: Gas Draining with padding","details":"### Details\nWhen the server acts as the fee_payer, `mppx` 0.6.27 validates calldata using viem's `decodeFunctionData`, which is lenient about trailing bytes. The `FeePayerPolicy` caps `gas_limit` (≤ 2 M) and `max_fee_per_gas` (≤ 100 Gwei) but does **not** check calldata length.\n\nTempo uses legacy calldata gas pricing: **16 gas per non-zero byte**. Appending `N` bytes of `0x01` padding inflates actual gas used by `N × 16` while keeping `gas_limit` and `max_fee_per_gas` within policy caps. The server cosigns and broadcasts the padded transaction, draining its fee-payer wallet.\n\n**Vulnerable code path:** `FeePayerPolicy` in `fee-payer.ts` (mppx 0.6.27) enforces `maxGas = 2_000_000` and `maxFeePerGas = 100 Gwei` but has no `calldata.length` bound. The policy check passes because the inflated gas comes from intrinsic calldata cost, not the declared `gas_limit`.\n\n**Note:** In the experiment, a 16 KB `max_header_length` is enforced, which caps the maximum effective padding at roughly 5,500 bytes. The default padding in this PoC (5,500 bytes) is within that limit.\n\n### PoC\nThe PoC is provided below. It is configured to reproduce the attack on Tempo Moderate testnet within a Docker environment. Download the PoC and run:\n```bash\nunzip mppx_typescript_PoC.zip\ncd mppx_typescript\ndocker build -t mppx-padding .\ndocker run --rm mppx-padding\n``` \nThere are more details in `mppx_typescript/README.md`\n\n### Impact\nA malicious client can force the server to pay ~**5x** the normal transaction fee. This dramatically increases operational costs and completely destroys the profit margin on low-cost items.\n\nPlease provide a way to share the PoC in .zip format to you. Thank you!","aliases":["CVE-2026-63627"],"modified":"2026-09-22T21:00:04.733697025Z","published":"2026-09-22T20:34:17Z","database_specific":{"github_reviewed_at":"2026-09-22T20:34:17Z","nvd_published_at":null,"cwe_ids":["CWE-20"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/wevm/mppx/security/advisories/GHSA-727h-3vm5-qwq6"},{"type":"WEB","url":"https://github.com/wevm/mppx/pull/602"},{"type":"WEB","url":"https://github.com/wevm/mppx/commit/24ddcca719ae282977d8747309ed1275ea282b25"},{"type":"PACKAGE","url":"https://github.com/wevm/mppx"},{"type":"WEB","url":"https://github.com/wevm/mppx/releases/tag/mppx@0.8.2"}],"affected":[{"package":{"name":"mppx","ecosystem":"npm","purl":"pkg:npm/mppx"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.8.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-727h-3vm5-qwq6/GHSA-727h-3vm5-qwq6.json","last_known_affected_version_range":"\u003c 0.8.1"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}