github.com/klever-io/klever-go
Official Go implementation of the Klever blockchain protocol — high-performance node, KVM smart contracts, and CLI tools
Activity
- Latest release
- 3w ago
- Total releases
- 9
- Cadence
- ~22 days
- Last 12 months
- 8
Reach
- Stars
- 31
Details
- First release
- Sep 26, 2025
| Version | Released | |
|---|---|---|
v1.7.21-rc2
pre
2 CVEs
CVE-2026-55763
GO-2026-6323
GHSA-v358-wf77-39xv
Sep 02, 2026
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/klever-io/klever-go before v1.7.19-rc4. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-44697
GO-2026-5246
GHSA-87m7-qffr-542v
Jun 25, 2026
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.21-rc2
pre
Dependencies (54)
+ 46 more |
|
v1.7.21-rc1
pre
2 CVEs
CVE-2026-55763
GO-2026-6323
GHSA-v358-wf77-39xv
Sep 02, 2026
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/klever-io/klever-go before v1.7.19-rc4. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-44697
GO-2026-5246
GHSA-87m7-qffr-542v
Jun 25, 2026
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.21-rc1
pre
Dependencies (54)
+ 46 more |
|
v1.7.20
patch
2 CVEs
CVE-2026-55763
GO-2026-6323
GHSA-v358-wf77-39xv
Sep 02, 2026
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/klever-io/klever-go before v1.7.19-rc4. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-44697
GO-2026-5246
GHSA-87m7-qffr-542v
Jun 25, 2026
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.20
patch
Dependencies (54)
+ 46 more |
|
v1.7.19
patch
2 CVEs
CVE-2026-55763
GO-2026-6323
GHSA-v358-wf77-39xv
Sep 02, 2026
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/klever-io/klever-go before v1.7.19-rc4. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-44697
GO-2026-5246
GHSA-87m7-qffr-542v
Jun 25, 2026
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.19
patch
Dependencies (54)
+ 46 more |
|
v1.7.18
patch
5 CVEs
CVE-2026-55764
GO-2026-6330
GHSA-mrpp-v6pg-p54x
Sep 02, 2026
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go klever-go: SFT add-quantity Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55763
GO-2026-6323
GHSA-v358-wf77-39xv
Sep 02, 2026
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/klever-io/klever-go before v1.7.19-rc4. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54754
GO-2026-6315
GHSA-p7gw-2pcp-5pf8
Sep 02, 2026
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54755
GO-2026-6310
GHSA-cgc5-v3f2-8m2v
Sep 02, 2026
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-44697
GO-2026-5246
GHSA-87m7-qffr-542v
Jun 25, 2026
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.18
patch
Dependencies (54)
+ 46 more |
|
v1.7.17
patch
10 CVEs
CVE-2026-55764
GO-2026-6330
GHSA-mrpp-v6pg-p54x
Sep 02, 2026
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go klever-go: SFT add-quantity Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55763
GO-2026-6323
GHSA-v358-wf77-39xv
Sep 02, 2026
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/klever-io/klever-go before v1.7.19-rc4. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54754
GO-2026-6315
GHSA-p7gw-2pcp-5pf8
Sep 02, 2026
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54755
GO-2026-6310
GHSA-cgc5-v3f2-8m2v
Sep 02, 2026
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-47249
GO-2026-5685
GHSA-w342-mj6g-v9c4
Jun 25, 2026
Klever-Go KVM: Hash-array amplification in P2P resolver request handling in github.com/klever-io/klever-go Klever-Go KVM: Hash-array amplification in P2P resolver request handling in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52880
GO-2026-5686
GHSA-w4c6-7r69-w7j9
Jun 25, 2026
klever-go: REST API slow-header connection exhaustion via Gin Engine.Run in github.com/klever-io/klever-go klever-go: REST API slow-header connection exhaustion via Gin Engine.Run in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52878
GO-2026-5628
GHSA-rm5c-5x2p-48wr
Jun 25, 2026
Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt in github.com/klever-io/klever-go Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52879
GO-2026-5424
GHSA-hf2g-6j7h-98wg
Jun 25, 2026
klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS in github.com/klever-io/klever-go klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-49343
GO-2026-5379
GHSA-fw38-pc54-jvx9
Jun 25, 2026
Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS in github.com/klever-io/klever-go Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44697
GO-2026-5246
GHSA-87m7-qffr-542v
Jun 25, 2026
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.17
patch
Dependencies (54)
+ 46 more |
|
v1.7.16
patch
12 CVEs
CVE-2026-55764
GO-2026-6330
GHSA-mrpp-v6pg-p54x
Sep 02, 2026
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go klever-go: SFT add-quantity Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55763
GO-2026-6323
GHSA-v358-wf77-39xv
Sep 02, 2026
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/klever-io/klever-go before v1.7.19-rc4. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54754
GO-2026-6315
GHSA-p7gw-2pcp-5pf8
Sep 02, 2026
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54755
GO-2026-6310
GHSA-cgc5-v3f2-8m2v
Sep 02, 2026
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-47249
GO-2026-5685
GHSA-w342-mj6g-v9c4
Jun 25, 2026
Klever-Go KVM: Hash-array amplification in P2P resolver request handling in github.com/klever-io/klever-go Klever-Go KVM: Hash-array amplification in P2P resolver request handling in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52880
GO-2026-5686
GHSA-w4c6-7r69-w7j9
Jun 25, 2026
klever-go: REST API slow-header connection exhaustion via Gin Engine.Run in github.com/klever-io/klever-go klever-go: REST API slow-header connection exhaustion via Gin Engine.Run in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52878
GO-2026-5628
GHSA-rm5c-5x2p-48wr
Jun 25, 2026
Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt in github.com/klever-io/klever-go Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46403
GO-2026-5461
GHSA-jc6w-wmfc-fh33
Jun 25, 2026
Klever-Go KVM read-only execution can commit contract delete and upgrade side effects in github.com/klever-io/klever-go Klever-Go KVM read-only execution can commit contract delete and upgrade side effects in github.com/klever-io/klever-go Fixed in
1.7.17
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52879
GO-2026-5424
GHSA-hf2g-6j7h-98wg
Jun 25, 2026
klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS in github.com/klever-io/klever-go klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-49343
GO-2026-5379
GHSA-fw38-pc54-jvx9
Jun 25, 2026
Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS in github.com/klever-io/klever-go Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44697
GO-2026-5246
GHSA-87m7-qffr-542v
Jun 25, 2026
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5204
GHSA-74m6-4hjp-7226
Jun 25, 2026
Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS) in github.com/klever-io/klever-go Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS) in github.com/klever-io/klever-go Fixed in
1.7.17
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.16
patch
Dependencies (54)
+ 46 more |
|
v1.7.15
patch
12 CVEs
CVE-2026-55764
GO-2026-6330
GHSA-mrpp-v6pg-p54x
Sep 02, 2026
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go klever-go: SFT add-quantity Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55763
GO-2026-6323
GHSA-v358-wf77-39xv
Sep 02, 2026
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/klever-io/klever-go before v1.7.19-rc4. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54754
GO-2026-6315
GHSA-p7gw-2pcp-5pf8
Sep 02, 2026
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54755
GO-2026-6310
GHSA-cgc5-v3f2-8m2v
Sep 02, 2026
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-47249
GO-2026-5685
GHSA-w342-mj6g-v9c4
Jun 25, 2026
Klever-Go KVM: Hash-array amplification in P2P resolver request handling in github.com/klever-io/klever-go Klever-Go KVM: Hash-array amplification in P2P resolver request handling in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52880
GO-2026-5686
GHSA-w4c6-7r69-w7j9
Jun 25, 2026
klever-go: REST API slow-header connection exhaustion via Gin Engine.Run in github.com/klever-io/klever-go klever-go: REST API slow-header connection exhaustion via Gin Engine.Run in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52878
GO-2026-5628
GHSA-rm5c-5x2p-48wr
Jun 25, 2026
Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt in github.com/klever-io/klever-go Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46403
GO-2026-5461
GHSA-jc6w-wmfc-fh33
Jun 25, 2026
Klever-Go KVM read-only execution can commit contract delete and upgrade side effects in github.com/klever-io/klever-go Klever-Go KVM read-only execution can commit contract delete and upgrade side effects in github.com/klever-io/klever-go Fixed in
1.7.17
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52879
GO-2026-5424
GHSA-hf2g-6j7h-98wg
Jun 25, 2026
klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS in github.com/klever-io/klever-go klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-49343
GO-2026-5379
GHSA-fw38-pc54-jvx9
Jun 25, 2026
Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS in github.com/klever-io/klever-go Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44697
GO-2026-5246
GHSA-87m7-qffr-542v
Jun 25, 2026
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5204
GHSA-74m6-4hjp-7226
Jun 25, 2026
Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS) in github.com/klever-io/klever-go Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS) in github.com/klever-io/klever-go Fixed in
1.7.17
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.15
patch
Dependencies (54)
+ 46 more |
|
v1.7.14
initial
12 CVEs
CVE-2026-55764
GO-2026-6330
GHSA-mrpp-v6pg-p54x
Sep 02, 2026
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go klever-go: SFT add-quantity Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55763
GO-2026-6323
GHSA-v358-wf77-39xv
Sep 02, 2026
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/klever-io/klever-go before v1.7.19-rc4. References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54754
GO-2026-6315
GHSA-p7gw-2pcp-5pf8
Sep 02, 2026
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54755
GO-2026-6310
GHSA-cgc5-v3f2-8m2v
Sep 02, 2026
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go Fixed in
1.7.19
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-47249
GO-2026-5685
GHSA-w342-mj6g-v9c4
Jun 25, 2026
Klever-Go KVM: Hash-array amplification in P2P resolver request handling in github.com/klever-io/klever-go Klever-Go KVM: Hash-array amplification in P2P resolver request handling in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52880
GO-2026-5686
GHSA-w4c6-7r69-w7j9
Jun 25, 2026
klever-go: REST API slow-header connection exhaustion via Gin Engine.Run in github.com/klever-io/klever-go klever-go: REST API slow-header connection exhaustion via Gin Engine.Run in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52878
GO-2026-5628
GHSA-rm5c-5x2p-48wr
Jun 25, 2026
Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt in github.com/klever-io/klever-go Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46403
GO-2026-5461
GHSA-jc6w-wmfc-fh33
Jun 25, 2026
Klever-Go KVM read-only execution can commit contract delete and upgrade side effects in github.com/klever-io/klever-go Klever-Go KVM read-only execution can commit contract delete and upgrade side effects in github.com/klever-io/klever-go Fixed in
1.7.17
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52879
GO-2026-5424
GHSA-hf2g-6j7h-98wg
Jun 25, 2026
klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS in github.com/klever-io/klever-go klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-49343
GO-2026-5379
GHSA-fw38-pc54-jvx9
Jun 25, 2026
Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS in github.com/klever-io/klever-go Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS in github.com/klever-io/klever-go Fixed in
1.7.18
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-44697
GO-2026-5246
GHSA-87m7-qffr-542v
Jun 25, 2026
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5204
GHSA-74m6-4hjp-7226
Jun 25, 2026
Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS) in github.com/klever-io/klever-go Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS) in github.com/klever-io/klever-go Fixed in
1.7.17
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.14
initial
Dependencies (54)
+ 46 more |