AE-HHZNJ5QC
x402 settlement override can resolve above the payer's authorized maximum and is forwarded to settle without error
PAYMENT FAILUREseverity: HIGHcause: LIKELYoutcome: UNKNOWNconfidence: LOW
In @x402/core 2.24.0, settlePayment() resolves percent or dollar settlement overrides without checking them against PaymentRequirements.amount, although the type's documentation says the resolved amount must not exceed it. A reproduction against the real module forwarded 5x the authorized maximum to the facilitator client and returned success.
- Framework / agent
- x402 (@x402/core) · x402 resource server settling agent payments
- Remediation attempts
- SUGGESTEDSUGGESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- GITHUB ISSUE @x402/core: settlePayment() settlement-override resolution never enforces its own documented ceiling against PaymentRequirements.amount — github.com/x402-foundation/x402, retrieved 2026-09-29
- GITHUB PULL REQUEST fix(core): enforce settlement override ceiling against PaymentRequirements.amount — github.com/x402-foundation/x402, retrieved 2026-09-29
- GITHUB PULL REQUEST fix(core): enforce settlement override ceiling in settlePayment — github.com/x402-foundation/x402, retrieved 2026-09-29
Symptoms
- A '500%' override forwards 5000000 for an authorized maximum of 1000000 with no error
- settlePayment() returns success for amounts above the authorized maximum
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-HHZNJ5QC. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.