Klever
Klever-go: vulnerabilidades y CVE
Klever-go tiene 18 vulnerabilidades publicadas, 18 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses18
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86065 | Alta (7.5) | 0.35% | — | 23 sept 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/api/websocket/routes.go accepts unauthenticated WebSocket clients with… |
| CVE-2026-86064 | Alta (8.6) | 0.40% | — | 23 sept 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.go does not require… |
| CVE-2026-82409 | Alta (8.4) | 0.27% | — | 23 sept 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and… |
| CVE-2026-82407 | Alta (7) | 0.43% | — | 23 sept 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.go Register and the runtime validator update path accept a submitted BLSPublicKey without curve,… |
| CVE-2026-82406 | Alta (7.1) | 0.34% | — | 23 sept 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/market.go Buy does not check IsClaimed before accepting a bid. A seller can use the… |
| CVE-2026-82405 | Alta (8.7) | 0.26% | — | 23 sept 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission built-in authorizes replacement of a target account's permissions by checking attacker-controlled… |
| CVE-2026-55764 | Alta (8.7) | 0.54% | — | 28 ago 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role holder to bypass a finite per-nonce MaxSupply on the semi-fungible token add-quantity path. In… |
| CVE-2026-55763 | Alta (8.7) | 0.51% | — | 28 ago 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the split loop and after the… |
| CVE-2026-54755 | Crítica (9.6) | 0.56% | — | 28 ago 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and… |
| CVE-2026-54754 | Crítica (9.6) | 0.43% | — | 28 ago 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading… |
| CVE-2026-52880 | Alta (7.5) | 0.49% | — | 7 ago 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run… |
| CVE-2026-52879 | Alta (7.5) | 0.49% | — | 7 ago 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message before the… |
| CVE-2026-52878 | Alta (7.5) | 0.49% | — | 7 ago 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is… |
| CVE-2026-49343 | Media (5.9) | 0.41% | — | 7 ago 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a resource-exhaustion flaw that leaks bounded throttler slots on error… |
| CVE-2026-47249 | Alta (7.5) | 0.49% | — | 7 ago 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a compressed… |
| CVE-2026-58262 | Alta (7.1) | 0.16% | — | 7 ago 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits of the PubKeysBitmap toward the two-thirds validator quorum. These… |
| CVE-2026-46403 | Media (6.3) | 0.45% | — | 21 jul 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the previous read-only state,… |
| CVE-2026-44697 | Alta (8.6) | 0.46% | — | 29 may 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.