Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34209

28
FAUCET Score

CVE-2026-34209 is a high-severity vulnerability (CVSS 7.5) affecting the mppx TypeScript interface for machine payments protocol, specifically versions prior to 0.4.11. The flaw lies in the tempo/session cooperative close handler, which improperly validates close voucher amounts using "<" instead of "<=" against the on-chain settled amount. This allows an unauthenticated attacker to submit a close voucher exactly equal to the settled amount, effectively closing or griefing a payment channel without committing new funds, impacting integrity. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered some community discussion on platforms like Bluesky and Mastodon.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.4.11CPE matchmatch criteria
cpe:2.3:a:wevm:mppx:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
28.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0036 is in the 9th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: mppxFixed in: 0.4.11

Vendor Advisories (1)

npmGHSA-mv9j-8jvg-j8mrhigh

mppx: Tempo has a session close voucher bypass vulnerability due to settled amount equality

Mar 29, 2026

References

github.com / wevm/mppx/commit/94088246ee18f21b5d6be40d9e7a464f5a280bfb
Patch
github.com / wevm/mppx/releases/tag/[email protected]
Release Notes
github.com / wevm/mppx/security/advisories/GHSA-mv9j-8jvg-j8mr
PatchVendor Advisory