go

github.com/klever-io/klever-go

View on go registry
30 Total advisories
30 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/klever-io/klever-go is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
Go

CVE-2026-82406

Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace

UNKNOWN
Go

CVE-2026-82407

Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS

UNKNOWN
Go

CVE-2026-82409

Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery

HIGH 7.5
Go

CVE-2026-86065

Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)

UNKNOWN
Go

CVE-2026-82405

Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller

HIGH 8.6
Go

CVE-2026-86064

Klever-Go: /log controls global node logging

CRITICAL 9.6
Go

CVE-2026-54755

Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)

UNKNOWN
Go

CVE-2026-55764

klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply

UNKNOWN
Go

CVE-2026-54755

Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go

UNKNOWN
Go

CVE-2026-55764

klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go

CRITICAL 9.6
Go

CVE-2026-54754

Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)

UNKNOWN
Go

CVE-2026-55763

klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits

UNKNOWN
Go

CVE-2026-55763

klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go

UNKNOWN
Go

CVE-2026-54754

Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go

HIGH 8.6
Go

CVE-2026-44697

Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload

HIGH 7.5
Go

CVE-2026-52879

klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS

HIGH 7.5
Go

CVE-2026-52878

Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt

HIGH 7.5
Go

CVE-2026-52880

klever-go: REST API slow-header connection exhaustion via Gin Engine.Run

MEDIUM 6.3
Go

CVE-2026-46403

Klever-Go KVM read-only execution can commit contract delete and upgrade side effects

HIGH 7.5
Go

CVE-2026-47249

Klever-Go KVM: Hash-array amplification in P2P resolver request handling

UNKNOWN
Go

CVE-2026-52878

Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt in github.com/klever-io/klever-go

UNKNOWN
Go

CVE-2026-47249

Klever-Go KVM: Hash-array amplification in P2P resolver request handling in github.com/klever-io/klever-go

UNKNOWN
Go

CVE-2026-52880

klever-go: REST API slow-header connection exhaustion via Gin Engine.Run in github.com/klever-io/klever-go

UNKNOWN
Go

CVE-2026-46403

Klever-Go KVM read-only execution can commit contract delete and upgrade side effects in github.com/klever-io/klever-go

UNKNOWN
Go

CVE-2026-52879

klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS in github.com/klever-io/klever-go

HIGH 7.5
Go

GO-2026-5204

Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS)

MEDIUM 5.9
Go

CVE-2026-49343

Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS

UNKNOWN
Go

CVE-2026-49343

Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS in github.com/klever-io/klever-go

UNKNOWN
Go

CVE-2026-44697

Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go

UNKNOWN
Go

GHSA-74m6-4hjp-7226

Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS) in github.com/klever-io/klever-go

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes