github.com/klever-io/klever-go
Go17 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/klever-io/klever-gopage 1 of 1
- CVE-2026-44697HIGHCVSS 8.6EG 8.62026-05-29
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that participates in a topic served …
- CVE-2026-46403MEDIUMCVSS 6.3EG 6.3fixed in 1.7.172026-05-21
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the previous read-only state, sets `runtime.SetReadOn…
- CVE-2026-47249HIGHCVSS 7.5EG 7.5fixed in 1.7.182026-06-05
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a compressed RequestDataType_HashArrayType …
- CVE-2026-49343MEDIUMCVSS 5.9EG 5.9fixed in 1.7.182026-06-05
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a resource-exhaustion flaw that leaks bounded throttler slots on error paths. In syncDataTri…
- CVE-2026-52878HIGHCVSS 7.5EG 7.5fixed in 1.7.182026-06-05
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission cau…
- CVE-2026-52879HIGHCVSS 7.5EG 7.5fixed in 1.7.182026-06-05
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message before the processor-level antiflood layer…
- CVE-2026-52880HIGHCVSS 7.5EG 7.5fixed in 1.7.182026-06-05
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, wh…
- CVE-2026-54754CRITICALCVSS 9.6EG 9.6fixed in 1.7.192026-08-28
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPerce…
- CVE-2026-54755CRITICALCVSS 9.6EG 9.6fixed in 1.7.192026-08-28
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and…
- CVE-2026-55763HIGHCVSS 8.7EG 8.7fixed in 1.7.19-rc42026-08-28
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the split loop and after the royaltiesToPay <= 0 early r…
- CVE-2026-55764HIGHCVSS 8.7EG 8.7fixed in 1.7.192026-08-28
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role holder to bypass a finite per-nonce MaxSupply on the semi-fungible token add-quantity path. In core/kapp/systemAccount/syst…
- CVE-2026-82405HIGHCVSS 8.7EG 8.7fixed in 1.7.202026-09-23
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission built-in authorizes replacement of a target account's permissions by checking attacker-controlled vmInput.RecipientAdd…
- CVE-2026-82406HIGHCVSS 7.1EG 7.1fixed in 1.7.202026-09-23
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/market.go Buy does not check IsClaimed before accepting a bid. A seller can use the Claim seller-accept…
- CVE-2026-82407HIGHCVSS 7.0EG 7.0fixed in 1.7.202026-09-23
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.go Register and the runtime validator update path accept a submitted BLSPublicKey without curve, prime-order subgroup, o…
- CVE-2026-82409HIGHCVSS 8.4EG 8.4fixed in 1.7.202026-09-23
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and NDJSON request with…
- CVE-2026-86064HIGHCVSS 8.6EG 8.6fixed in 1.7.202026-09-23
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.go does not require authentication. The f…
- CVE-2026-86065HIGHCVSS 7.5EG 7.5fixed in 1.7.202026-09-23
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/api/websocket/routes.go accepts unauthenticated WebSocket clients with permissive origin handling, d…
Check whether github.com/klever-io/klever-go is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/klever-io/klever-go CVEs against the assets you own.
Book a Demo →