vulns.co
/
GKData.io MCP

Paymenter · 1 min read

Paymenter: refund entitlement and ledger changes need one atomic transition

The maintainer traces duplicate downgrade credits to an eligibility check separated from the later balance change, without transactional isolation. A pending-operation guard did not protect the whole transition. The failed invariant was one legitimate refund per service downgrade.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial lesson: model refund eligibility, transition identity and ledger mutation as one atomic decision. Local regression checks should establish that repeated or overlapping processing cannot mint additional entitlement. The advisory identifies 1.5.7 as patched; its release notes explicitly link the fix.

Before reading

  • Basic application state machines, authorization and database transaction concepts

Context and limits

  • Affected versions are listed as 1.5.6 and earlier. The reported scenario requires an authenticated customer and an active service eligible for downgrade.
  • The maintainer reports excess spendable credit and potential operator loss, but supplies no production incident or independently measured loss. This review does not establish deployment exposure.
  • The advisory header identifies CorwinDev as the publishing account, and Credits lists Pig-Tail as Reporter and CorwinDev as Remediation developer. The reviewed advisory provides no explicit article byline; these publication and credit roles do not establish article authorship. The advisory assigns CVE-2026-71537.
  • The release page displays July 25 without a year in the reviewed rendering. No full patch-release date is asserted. Resource edition and version-release date remain null.

Sources and provenance

  1. Credit-refund double-spend race condition in service downgrade (doUpgrade) Paymenter · reviewed 2026-10-03
  2. Paymenter v1.5.7 release Paymenter · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software