github.com/klever-io/klever-go
Go11 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/klever-io/klever-gopage 1 of 1
- CVE-2026-44697HIGHCVSS 8.6EG 8.62026-05-29
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that participates in a topic served …
- CVE-2026-46403MEDIUMCVSS 6.3EG 6.3✓ Fixed in 1.7.172026-05-21
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the previous read-only state, sets `runtime.SetReadOn…
- CVE-2026-47249HIGHCVSS 7.5EG 7.5✓ Fixed in 1.7.182026-06-05
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a compressed RequestDataType_HashArrayType …
- CVE-2026-49343MEDIUMCVSS 5.9EG 5.9✓ Fixed in 1.7.182026-06-05
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a resource-exhaustion flaw that leaks bounded throttler slots on error paths. In syncDataTri…
- CVE-2026-52878HIGHCVSS 7.5EG 7.5✓ Fixed in 1.7.182026-06-05
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission cau…
- CVE-2026-52879HIGHCVSS 7.5EG 7.5✓ Fixed in 1.7.182026-06-05
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message before the processor-level antiflood layer…
- CVE-2026-52880HIGHCVSS 7.5EG 7.5✓ Fixed in 1.7.182026-06-05
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, wh…
- CVE-2026-54754CRITICALCVSS 9.6EG 9.6✓ Fixed in 1.7.192026-08-28
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPerce…
- CVE-2026-54755CRITICALCVSS 9.6EG 9.6✓ Fixed in 1.7.192026-08-28
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and…
- CVE-2026-55763HIGHCVSS 8.7EG 8.7✓ Fixed in 1.7.19-rc42026-08-28
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the split loop and after the royaltiesToPay <= 0 early r…
- CVE-2026-55764HIGHCVSS 8.7EG 8.7✓ Fixed in 1.7.192026-08-28
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role holder to bypass a finite per-nonce MaxSupply on the semi-fungible token add-quantity path. In core/kapp/systemAccount/syst…
Check whether github.com/klever-io/klever-go is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/klever-io/klever-go CVEs against the assets you own.
Start Free Scan →