VYPR

Go modules package

github.com/klever-io/klever-go

pkg:golang/github.com/klever-io/klever-go

Vulnerabilities (5)

  • CVE-2026-86065HigSep 23, 2026
    affected < 1.7.20fixed 1.7.20

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/api/websocket/routes.go accepts unauthenticated WebSocket clients with permissive origin handling, does not call SetReadLimit to bound messag

  • CVE-2026-86064HigSep 23, 2026
    affected < 1.7.20fixed 1.7.20

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.go does not require authentication. The first client message is parsed as a logger

  • CVE-2026-82405HigSep 23, 2026
    affected < 1.7.20fixed 1.7.20

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission built-in authorizes replacement of a target account's permissions by checking attacker-controlled vmInput.RecipientAddr instead of authenticated vmInput.Caller

  • CVE-2026-47249HigAug 7, 2026
    affected < 1.7.18fixed 1.7.18

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a compressed RequestDataType_HashArrayType direct request that is only 442 bytes on

  • CVE-2026-44697HigMay 29, 2026
    affected <= 1.7.16

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that participates in a topic served by MultiDataInterceptor to allocate multi