VYPR

Go modules package

github.com/klever-io/klever-go

pkg:golang/github.com/klever-io/klever-go

Vulnerabilities (2)

  • CVE-2026-47249higJun 5, 2026
    affected < 1.7.18fixed 1.7.18

    ### Summary A connected peer can send a compressed `RequestDataType_HashArrayType` direct request that is only `442` bytes on the wire but expands into `200000` decoded hash entries inside the resolver path. On `klever-go` `v1.7.17`, this allows remote memory and CPU amplificatio

  • CVE-2026-44697HigMay 29, 2026
    affected <= 1.7.16

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that participates in a topic served by MultiDataInterceptor to allocate multi