AGR-2026-096 — Receipt parser accepts non-success statuses
Last observed by the head-to-head audit at 2026-09-14T09:17:13.387847Z.
Audited heads
| Target |
Repository |
Commit |
Conformance |
Semantic review |
typescript |
wevm/mppx |
3c14a65a7ea5 |
Complete |
Reference |
java |
stripe/mpp-java |
ca57f0998545 |
Complete |
Complete |
go |
tempoxyz/mpp-go |
9fcf9a47c61b |
Complete |
Complete |
python |
tempoxyz/pympp |
7988d1cda5c4 |
Complete |
Complete |
ruby |
stripe/mpp-rb |
3b9e2923c67b |
Complete |
Complete |
rust |
tempoxyz/mpp-rs |
d859a13d74ef |
Complete |
Complete |
Finding
- Fingerprint:
semantic:receipts/require-success-status
- Source: semantic
- Affected SDKs:
java
- Clean SDKs: none
- Not reported by semantic review:
go, python, ruby, rust
- Canonical reference:
draft-httpauth-payment-01 §5.3 (Payment-Receipt Header): status MUST be "success"
- Severity: medium
- Confidence: high
Evidence
| SDK |
Canonical evidence |
SDK evidence |
Suggested test |
java |
shape.status — Defines receipt status as the literal value "success"; Receipt.from and deserialize enforce this schema. |
parsePaymentReceipt — Reads status as an arbitrary string and rejects only a missing value. |
Decode a syntactically valid receipt whose status is "failed" and assert that receipt parsing rejects it. |
java: Canonical mppx validates the receipt status as the literal "success". The Java parser only checks that status exists, so values such as "failed" are accepted as valid receipts. Consumers may consequently treat an error-like or forged result as a protocol-valid successful payment receipt.
Available /ag commands
Post a command as a new comment. Only configured maintainers can run these commands.
| Command |
What it does |
/ag status |
Reports the current state of linked remediation pull requests. |
/ag fix is unavailable for java because the affected SDK is configured for notification-only automation.
AGR-2026-096 — Receipt parser accepts non-success statuses
Last observed by the head-to-head audit at
2026-09-14T09:17:13.387847Z.Audited heads
typescriptwevm/mppx3c14a65a7ea5javastripe/mpp-javaca57f0998545gotempoxyz/mpp-go9fcf9a47c61bpythontempoxyz/pympp7988d1cda5c4rubystripe/mpp-rb3b9e2923c67brusttempoxyz/mpp-rsd859a13d74efFinding
semantic:receipts/require-success-statusjavago,python,ruby,rustdraft-httpauth-payment-01 §5.3 (Payment-Receipt Header): status MUST be "success"Evidence
javajava: Canonical mppx validates the receipt status as the literal "success". The Java parser only checks that status exists, so values such as "failed" are accepted as valid receipts. Consumers may consequently treat an error-like or forged result as a protocol-valid successful payment receipt.
Available
/agcommandsPost a command as a new comment. Only configured maintainers can run these commands.
/ag status