---
id: CVE-2026-48100
title: >-
  Payy is an Ethereum L2 zk-rollup for privacy preserving and regulatory
  compliant transactions
summary: >-
  Payy is an Ethereum L2 zk-rollup for privacy preserving and regulatory
  compliant transactions. Prior to version 1.3.0, agg_agg forwards the compacted
  message stream from its inner proofs into a public messages: [Field; 1000]
  array, but i…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-349
vendor: polybase
product: payy
affected:
  - payy < 1.3.0
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T18:17:22.120'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48100'
references:
  - url: 'https://github.com/polybase/payy/security/advisories/GHSA-fhxc-63vg-9gwr'
    label: security-advisories@github.com
  - url: 'https://github.com/polybase/payy/security/advisories/GHSA-fhxc-63vg-9gwr'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-28T17:20:42.562536Z'
cvssSource: cna
ingestedAt: '2026-09-28T17:16:27.811Z'
---

## Overview

Payy is an Ethereum L2 zk-rollup for privacy preserving and regulatory compliant transactions. Prior to version 1.3.0, agg_agg forwards the compacted message stream from its inner proofs into a public messages: [Field; 1000] array, but it never checks that the unused tail of the outer array is zero. A registered prover can build a valid agg_final proof for an approved rollup block while inserting an extra burn message after the real messages. RollupV1.verifyRollup() then parses that public input as a normal burn and transfers USDC from the rollup contract to the attacker. This is a severe circuit soundness failure: the proof system accepts a public statement whose messages array is not fully derived from the verified inner proofs. On the current deployment, verifyRollup() is restricted to the existing allowlisted prover, so a fresh public caller cannot submit the invalid proof directly. That gate limits who can reach L1 today; it does not make the circuit statement sound. The issue becomes permissionless under the prover model described in the Payy whitepaper. Section 3.3.2 states: "To join as a prover, the prover is required to submit a small stake", and Section 3.3.1 states that if a prover fails to submit, "other nodes can submit the block proof instead." In that model, an attacker only needs to become a registered prover and use public validator approval data for an already approved block. This issue has been patched in version 1.3.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
