Vulnerabilities in klever-io

18 results
Vexday analysis

A plataforma Klever-io registra apenas 2 vulnerabilidades catalogadas, ambas publicadas recentemente (últimos 90 dias), porém nenhuma está sob exploração ativa conhecida. As falhas identificadas relacionam-se primariamente a CWE-409 (Improper Handling of Highly Compressed Data) e não atingem criticidade máxima, sugerindo um perfil de risco baixo a moderado no contexto atual.

CVE-2026-54755CRITICALKlever-Go: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)EPSS 0.6%CVE-2026-55764HIGHKlever-Go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupplyEPSS 0.5%CVE-2026-55763HIGHKlever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splitsEPSS 0.5%CVE-2026-52879HIGHKlever-Go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoSEPSS 0.5%CVE-2026-52878HIGHKlever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can halt the chainEPSS 0.5%CVE-2026-47249HIGHKlever-Go KVM: Hash-array amplification in P2P resolver request handlingEPSS 0.5%CVE-2026-52880HIGHKlever-Go: REST API slow-header connection exhaustion via Gin Engine.RunEPSS 0.5%CVE-2026-44697HIGHKlever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payloadEPSS 0.5%CVE-2026-46403MEDIUMKlever-Go KVM read-only execution can commit contract delete and upgrade side effectsEPSS 0.4%CVE-2026-82407HIGHKlever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoSEPSS 0.4%CVE-2026-54754CRITICALKlever-Go: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)EPSS 0.4%CVE-2026-49343MEDIUMKlever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoSEPSS 0.4%CVE-2026-86064HIGHKlever-Go: /log controls global node loggingEPSS 0.4%CVE-2026-86065HIGHKlever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)EPSS 0.4%CVE-2026-82406HIGHKlever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplaceEPSS 0.3%CVE-2026-82409HIGHKlever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgeryEPSS 0.3%CVE-2026-82405HIGHKlever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated callerEPSS 0.3%CVE-2026-58262HIGHKlever-Go: PubKeysBitmap padding bits bypass the BLS signature quorumEPSS 0.2%