Vulnerabilidades em klever-io
8 resultadosAnálise Vexday
A plataforma Klever-io registra apenas 2 vulnerabilidades catalogadas, ambas publicadas recentemente (últimos 90 dias), porém nenhuma está sob exploração ativa conhecida. As falhas identificadas relacionam-se primariamente a CWE-409 (Improper Handling of Highly Compressed Data) e não atingem criticidade máxima, sugerindo um perfil de risco baixo a moderado no contexto atual.
CVE-2026-44697HIGHKlever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payloadEPSS 0.4%CVE-2026-46403MEDIUMKlever-Go KVM read-only execution can commit contract delete and upgrade side effectsEPSS 0.3%CVE-2026-52880HIGHKlever-Go: REST API slow-header connection exhaustion via Gin Engine.RunEPSS 0.3%CVE-2026-52879HIGHKlever-Go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoSEPSS 0.3%CVE-2026-52878HIGHKlever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can halt the chainEPSS 0.3%CVE-2026-47249HIGHKlever-Go KVM: Hash-array amplification in P2P resolver request handlingEPSS 0.3%CVE-2026-49343MEDIUMKlever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoSEPSS 0.3%CVE-2026-58262HIGHKlever-Go: PubKeysBitmap padding bits bypass the BLS signature quorumEPSS 0.1%