{"id":"GHSA-vc9j-9wph-qghj","summary":"mppx: Gas Draining with access list","details":"### Details\nWhen the server acts as the fee_payer, `mppx` 0.6.27 copies the client-supplied EIP-2930 access list verbatim into the cosigned fee-payer transaction. The TypeScript SDK's fee-payer cosigning path accepts any `access_list` the client includes in the 0x78 `FeePayerEnvelope` without inspecting its length or contents.\n\nAccess list gas is charged **intrinsically** — before any opcode executes — regardless of whether the listed addresses are ever touched.\n\nAn attacker submits a valid `transferWithMemo` alongside fabricated address-only access list entries. The server validates calldata and gas parameters but never inspects `access_list` length. It cosigns and broadcasts a transaction that costs the fee-payer wallet `N × 2,400` extra gas per request with no corresponding work performed on-chain.\n\nAt the default of 180 entries and 100 Gwei `max_fee_per_gas`, this inflates the fee-payer cost from the normal ~51,287 gas to ~483,287 gas — a **9.4× multiplier** — while staying within the `FeePayerPolicy` cap of 500K gas, the Node.js 16 KB header limit, and the Moderato RPC's `eth_call` simulation budget (verified empirically at 180 entries).\n\n### PoC\nThe PoC is provided below. It is configured to reproduce the attack on Tempo Moderate testnet within a Docker environment. Download the PoC and run:\n```bash\nunzip mppx_typescript_PoC.zip\ncd mppx_typescript\ndocker build -t mppx-typescript-access-list .\ndocker run --rm mppx-typescript-access-list\n``` \nThere are more details in `mppx_typescript/README.md`\n\n### Impact\nA malicious client can force the server to pay ~**9.4x** the normal transaction fee. This dramatically increases operational costs and completely destroys the profit margin on low-cost items.","aliases":["CVE-2026-63628"],"modified":"2026-09-22T21:00:10.495528816Z","published":"2026-09-22T20:34:19Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-20"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-22T20:34:19Z"},"references":[{"type":"WEB","url":"https://github.com/wevm/mppx/security/advisories/GHSA-vc9j-9wph-qghj"},{"type":"WEB","url":"https://github.com/wevm/mppx/pull/602"},{"type":"WEB","url":"https://github.com/wevm/mppx/commit/24ddcca719ae282977d8747309ed1275ea282b25"},{"type":"PACKAGE","url":"https://github.com/wevm/mppx"},{"type":"WEB","url":"https://github.com/wevm/mppx/releases/tag/mppx@0.8.2"}],"affected":[{"package":{"name":"mppx","ecosystem":"npm","purl":"pkg:npm/mppx"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.8.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-vc9j-9wph-qghj/GHSA-vc9j-9wph-qghj.json"}}],"schema_version":"1.9.0"}