x402 is vulnerable to Replay Attacks
47
Medium Risk
Affected versions of this package are vulnerable to duplicate transaction attacks in Solana payment flows because identical transaction payloads can be generated under concurrent conditions. Since Solana rejects byte-identical transactions within the same blockhash window, attackers or high-throughput scenarios could trigger transaction collisions, leading to dropped or delayed payments. The issue is fixed by adding a unique memo with a random nonce to each transaction, ensuring every payment is distinct and preventing duplicate transaction conflicts.
You are affected if you are using a version that falls within the vulnerable range.
x402 is vulnerable to Replay Attacks in versions 0.1.0 - 2.0.0.
Upgrade the x402 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant