Packages

Elixir implementation of the Machine Payments Protocol (MPP) — HTTP 402 payment middleware for AI agents and machine-to-machine commerce. Supports Stripe, Tempo, generic EVM, Solana, and NEAR Intents payment methods with pluggable architecture.

Current section

7 Advisories

Jump to
EEF-CVE-2026-67581 CVE-2026-67581 GHSA-vp5h-xh25-44wf

On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay

August 19, 2026
CVSS
?
8.7 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Versions

>= 0.3.0 and < 0.6.3
EEF-CVE-2026-73541 CVE-2026-73541 GHSA-j4j7-7xpr-c7cr

Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain

August 19, 2026
CVSS
?
8.3 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0 and < 0.12.0
EEF-CVE-2026-73136 CVE-2026-73136 GHSA-34g7-vx6g-82mq

Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay

August 19, 2026
CVSS
?
8.2 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Versions

>= 0.6.1 and < 0.6.4
EEF-CVE-2026-73829 CVE-2026-73829 GHSA-w8j7-7qc3-5f24

Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race

August 19, 2026
CVSS
?
6.3 / 10.0 Medium
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0 and < 0.6.1
EEF-CVE-2026-59252 CVE-2026-59252 GHSA-vj8p-hp9x-gh47

Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain

July 17, 2026
CVSS
?
8.2 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0 and < 0.6.0
EEF-CVE-2026-59694 CVE-2026-59694 GHSA-qpxh-ff8m-c62v

Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment

July 17, 2026
CVSS
?
8.3 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0 and < 0.6.0
EEF-CVE-2026-59695 CVE-2026-59695 GHSA-vv77-66rf-pm86

Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain

July 17, 2026
CVSS
?
8.3 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.0 and < 0.6.0

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 50 100 150 200

this version

491

yesterday

85

last 7 days

156

all time

2 149

Last Updated

Aug 20, 2026

License

MIT

Build Tools

mix

Publisher

e.fu e.fu

Owners