CVE-2026-34209: mppx: Tempo has a session close voucher bypass vulnerability due to settled amount equality
(updated )
The tempo/session cooperative close handler validated the close voucher amount using < instead of <= against the on-chain settled amount. An attacker could submit a close voucher exactly equal to the settled amount, which would be accepted without committing any new funds, effectively closing or griefing the channel for free.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-34209 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →