pympp is vulnerable to Improper Input Validation
31
Low Risk
The FeePayerPolicy in pympp caps gas_limit and max_fee_per_gas when the server acts as a fee payer but does not validate the length of transaction calldata. Because non-zero calldata bytes cost gas under legacy pricing, appending non-zero byte padding inflates the real gas consumption of a transaction without breaching either cap. The server then cosigns and broadcasts the padded transaction, charging excessive fees to the fee-payer wallet. The fix adds calldata validation so oversized padded transactions are rejected before cosigning.
You are affected if you are using a version that falls within the vulnerable range and you operate the server as a fee payer using FeePayerPolicy.
pympp is vulnerable to Improper Input Validation in versions 0.0.1 - 0.9.0.
Upgrade the pympp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.