Dependency scanning
Check whether github.com/klever-io/klever-go is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-82406
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace
CVE-2026-82407
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS
CVE-2026-82409
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery
CVE-2026-86065
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)
CVE-2026-82405
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller
CVE-2026-86064
Klever-Go: /log controls global node logging
CVE-2026-54755
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
CVE-2026-55764
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply
CVE-2026-54755
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go
CVE-2026-55764
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go
CVE-2026-54754
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
CVE-2026-55763
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
CVE-2026-55763
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go
CVE-2026-54754
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go
CVE-2026-44697
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload
CVE-2026-52879
klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS
CVE-2026-52878
Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt
CVE-2026-52880
klever-go: REST API slow-header connection exhaustion via Gin Engine.Run
CVE-2026-46403
Klever-Go KVM read-only execution can commit contract delete and upgrade side effects
CVE-2026-47249
Klever-Go KVM: Hash-array amplification in P2P resolver request handling
CVE-2026-52878
Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt in github.com/klever-io/klever-go
CVE-2026-47249
Klever-Go KVM: Hash-array amplification in P2P resolver request handling in github.com/klever-io/klever-go
CVE-2026-52880
klever-go: REST API slow-header connection exhaustion via Gin Engine.Run in github.com/klever-io/klever-go
CVE-2026-46403
Klever-Go KVM read-only execution can commit contract delete and upgrade side effects in github.com/klever-io/klever-go
CVE-2026-52879
klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS in github.com/klever-io/klever-go
GO-2026-5204
Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS)
CVE-2026-49343
Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS
CVE-2026-49343
Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS in github.com/klever-io/klever-go
CVE-2026-44697
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go
GHSA-74m6-4hjp-7226
Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS) in github.com/klever-io/klever-go
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes