Packages

Elixir implementation of the Machine Payments Protocol (MPP) — HTTP 402 payment middleware for AI agents and machine-to-machine commerce. Supports Stripe, Tempo, generic EVM, Solana, Stellar, XRPL, and NEAR Intents payment methods with pluggable architecture.

Current section

13 Advisories

Jump to
EEF-CVE-2026-87119 CVE-2026-87119 GHSA-p9fv-9w58-95x2

mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed

September 22, 2026
EEF-CVE-2026-89420 CVE-2026-89420 GHSA-8c63-r789-xrrf

Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free

September 22, 2026
EEF-CVE-2026-88255 CVE-2026-88255 GHSA-8x7x-5j8g-8hcx

mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot

September 16, 2026
EEF-CVE-2026-89186 CVE-2026-89186 GHSA-82qh-vrvm-gqvc

mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches

September 16, 2026
EEF-CVE-2026-82750 CVE-2026-82750 GHSA-5qrp-r24c-w6jr

Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation

September 06, 2026
CVSS
?
8.3 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0 and < 0.16.1
EEF-CVE-2026-82751 CVE-2026-82751 GHSA-rpwj-vrf7-4x36

Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning

September 06, 2026
CVSS
?
8.3 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0 and < 0.16.1
EEF-CVE-2026-67581 CVE-2026-67581 GHSA-vp5h-xh25-44wf

On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay

August 19, 2026
CVSS
?
8.7 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Versions

>= 0.3.0 and < 0.6.3
EEF-CVE-2026-73541 CVE-2026-73541 GHSA-j4j7-7xpr-c7cr

Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain

August 19, 2026
CVSS
?
8.3 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0 and < 0.12.0
EEF-CVE-2026-73136 CVE-2026-73136 GHSA-34g7-vx6g-82mq

Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay

August 19, 2026
CVSS
?
8.2 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Versions

>= 0.6.1 and < 0.6.4
EEF-CVE-2026-73829 CVE-2026-73829 GHSA-w8j7-7qc3-5f24

Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race

August 19, 2026
CVSS
?
6.3 / 10.0 Medium
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0 and < 0.6.1
EEF-CVE-2026-59252 CVE-2026-59252 GHSA-vj8p-hp9x-gh47

Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain

July 17, 2026
CVSS
?
8.2 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0 and < 0.6.0
EEF-CVE-2026-59694 CVE-2026-59694 GHSA-qpxh-ff8m-c62v

Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment

July 17, 2026
CVSS
?
8.3 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0 and < 0.6.0
EEF-CVE-2026-59695 CVE-2026-59695 GHSA-vv77-66rf-pm86

Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain

July 17, 2026
CVSS
?
8.3 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0 and < 0.6.0

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 100 200 300 400

this version

936

yesterday

157

last 7 days

1 337

all time

4 711

Last Updated

Sep 17, 2026

License

MIT

Build Tools

mix

Publisher

e.fu e.fu

Owners