Junglewise Threat Intelligence

Klever klever-go connection exhaustion in REST API

Severity: high · CVSS 7.5 · Published 2026-06-05

Technologies: Klever.io Klever-Go, github.com/klever-io/klever-go (Go). Vendors: Klever.io, Go.

Executive brief

The Klever blockchain node software contains a vulnerability in its REST API that allows an attacker to crash or disable the service. By sending incomplete web requests and keeping them open, an attacker can exhaust the server's available connections, preventing legitimate users from querying the blockchain or performing operations. This results in a denial-of-service condition for the node's management and query interface.

Technical details

The Klever seednode and node REST APIs utilize the Gin web framework's `Engine.Run` method, which defaults to Go's `http.ListenAndServe`. This default configuration lacks `ReadHeaderTimeout`, `ReadTimeout`, and `MaxHeaderBytes` limits. An unauthenticated remote attacker can exploit this by initiating multiple HTTP connections and sending headers very slowly (Slowloris attack), eventually exhausting the file descriptor limit ('too many open files'). This prevents the server from accepting new legitimate connections. The vulnerability is present in `cmd/seednode/api` and `network/api` and was addressed in version 1.7.18 by implementing an explicit `http.Server` with defined timeouts.

Affected products

  • klever-io klever-go >= 1.7.14, <= 1.7.17

Timeline

  • 2026-06-02: disclosed
  • 2026-06-05: advisory
  • 2026-06-05: patched: Version 1.7.18 released

References

Related threats