CVE-2026-48100 - Payy: agg_agg trailing message slots are unconstrained and allow forged burn messages
CVE ID :CVE-2026-48100 Published : Sept. 28, 2026, 5:17 p.m. | 57 minutes ago Description :Payy is an Ethereum L2 zk-rollup for privacy preserving and regulatory compliant transactions. Prior to version 1.3.0, agg_agg forwards the compacted message stream from its inner proofs into a public...