{"schema_version":1,"title":"github.com/klever-io/klever-go (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 23 vulnerabilities in github.com/klever-io/klever-go (Go): 6 in the last 7 days and 11 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86065, was published on 23 September 2026.","url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go","json_url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":14,"all_time":23,"critical":2,"exploited":0,"last_7_days":6,"last_30_days":10,"last_90_days":11,"last_365_days":23},"latest":[{"cve":"CVE-2026-86065","cvss":7.5,"epss":0.0035,"slug":"cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/a","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:20.16+00:00","url":"https://junglewise.ai/threats/cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos"},{"cve":"CVE-2026-86064","cvss":8.6,"epss":0.004,"slug":"cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:19.96+00:00","url":"https://junglewise.ai/threats/cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration"},{"cve":"CVE-2026-82409","cvss":4,"epss":0.0027,"slug":"cve-2026-82409-klever-go-elasticsearch-injection-via-account-name","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts pla","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.893+00:00","url":"https://junglewise.ai/threats/cve-2026-82409-klever-go-elasticsearch-injection-via-account-name"},{"cve":"CVE-2026-82407","cvss":4,"epss":0.0043,"slug":"cve-2026-82407-klever-go-bls-public-key-validation-bypass-in-validator","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.go Register and the r","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.707+00:00","url":"https://junglewise.ai/threats/cve-2026-82407-klever-go-bls-public-key-validation-bypass-in-validator"},{"cve":"CVE-2026-82406","cvss":4,"epss":0.0034,"slug":"cve-2026-82406-klever-go-marketplace-buy-missing-isclaimed-guard","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/mark","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.547+00:00","url":"https://junglewise.ai/threats/cve-2026-82406-klever-go-marketplace-buy-missing-isclaimed-guard"},{"cve":"CVE-2026-82405","cvss":4,"epss":0.0026,"slug":"cve-2026-82405-klever-go-account-takeover-via-authorization-bypass-in","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission built-in authorizes","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.37+00:00","url":"https://junglewise.ai/threats/cve-2026-82405-klever-go-account-takeover-via-authorization-bypass-in"},{"cve":"CVE-2026-55764","cvss":4,"epss":0.0054,"slug":"cve-2026-55764-klever-go-sft-add-quantity-int64-overflow-bypasses-maxsupply","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role holder to bypass a finit","severity":"high","exploited":false,"published_at":"2026-08-28T23:17:07.22+00:00","url":"https://junglewise.ai/threats/cve-2026-55764-klever-go-sft-add-quantity-int64-overflow-bypasses-maxsupply"},{"cve":"CVE-2026-55763","cvss":4,"epss":0.0051,"slug":"cve-2026-55763-klever-klever-go-percentage-transfer-royalty-zero-debit-in","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accou","severity":"high","exploited":false,"published_at":"2026-08-28T22:16:51.72+00:00","url":"https://junglewise.ai/threats/cve-2026-55763-klever-klever-go-percentage-transfer-royalty-zero-debit-in"},{"cve":"CVE-2026-54755","cvss":9.6,"epss":0.0056,"slug":"cve-2026-54755-klever-integer-overflow-in-split-royalty-validation-enables","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunc","severity":"critical","exploited":false,"published_at":"2026-08-28T20:18:17.67+00:00","url":"https://junglewise.ai/threats/cve-2026-54755-klever-integer-overflow-in-split-royalty-validation-enables"},{"cve":"CVE-2026-54754","cvss":9.6,"epss":0.0043,"slug":"cve-2026-54754-klever-marketplace-settlement-mints-klv-when-referral-and-royalty","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go","severity":"critical","exploited":false,"published_at":"2026-08-28T20:18:17.533+00:00","url":"https://junglewise.ai/threats/cve-2026-54754-klever-marketplace-settlement-mints-klv-when-referral-and-royalty"},{"cve":"CVE-2026-46403","cvss":6.3,"epss":0.0045,"slug":"cve-2026-46403-klever-io-klever-go-protection-mechanism-failure-in-kvm-read-only","title":"Klever-io Klever-Go protection mechanism failure in KVM read-only execution","severity":"medium","exploited":false,"published_at":"2026-07-21T20:17:01.067+00:00","url":"https://junglewise.ai/threats/cve-2026-46403-klever-io-klever-go-protection-mechanism-failure-in-kvm-read-only"},{"cve":"CVE-2026-52880","cvss":3.1,"epss":0.0049,"slug":"cve-2026-52880-klever-go-rest-api-slow-header-connection-exhaustion-via-gin","title":"GO-2026-5686 - klever-go: REST API slow-header connection exhaustion via Gin Engine.Run in github.com/klever-io/klever-go","severity":"low","exploited":false,"published_at":"2026-06-25T22:34:38+00:00","url":"https://junglewise.ai/threats/cve-2026-52880-klever-go-rest-api-slow-header-connection-exhaustion-via-gin"},{"cve":"CVE-2026-52878","cvss":3.1,"epss":0.0049,"slug":"cve-2026-52878-klever-go-kvm-unauthenticated-remote-node-crash-nil-pointer-dos","title":"GO-2026-5628 - Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData)","severity":"low","exploited":false,"published_at":"2026-06-25T22:34:34+00:00","url":"https://junglewise.ai/threats/cve-2026-52878-klever-go-kvm-unauthenticated-remote-node-crash-nil-pointer-dos"},{"cve":"CVE-2026-52879","cvss":3.1,"epss":0.0049,"slug":"cve-2026-52879-klever-go-unbounded-goroutine-spawn-on-direct-message-ingress","title":"GO-2026-5424 - klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS in github.com/klever-io/klever-go","severity":"low","exploited":false,"published_at":"2026-06-25T22:34:31+00:00","url":"https://junglewise.ai/threats/cve-2026-52879-klever-go-unbounded-goroutine-spawn-on-direct-message-ingress"},{"slug":"go-2026-5204-klever-go-p2p-multidatainterceptor-leaks-global-throttler-a0b60bf5","title":"GO-2026-5204 - Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS) in github.com/klever-io/klever-go","severity":"info","exploited":false,"published_at":"2026-06-25T18:43:15+00:00","url":"https://junglewise.ai/threats/go-2026-5204-klever-go-p2p-multidatainterceptor-leaks-global-throttler-a0b60bf5"},{"cvss":7.5,"slug":"klever-io-klever-go-null-pointer-dereference-in-p2p-transaction-a0621e14","title":"Klever-io Klever-Go NULL pointer dereference in P2P transaction interceptor","severity":"high","exploited":false,"published_at":"2026-06-05T16:42:38+00:00","url":"https://junglewise.ai/threats/klever-io-klever-go-null-pointer-dereference-in-p2p-transaction-a0621e14"},{"cvss":7.5,"slug":"klever-klever-go-connection-exhaustion-in-rest-api-9b1a775a","title":"Klever klever-go connection exhaustion in REST API","severity":"high","exploited":false,"published_at":"2026-06-05T16:41:58+00:00","url":"https://junglewise.ai/threats/klever-klever-go-connection-exhaustion-in-rest-api-9b1a775a"},{"cvss":7.5,"slug":"klever-klever-go-unbounded-goroutine-spawn-in-directmessagehandler-8a95a76c","title":"Klever klever-go unbounded goroutine spawn in directMessageHandler","severity":"high","exploited":false,"published_at":"2026-06-05T16:41:23+00:00","url":"https://junglewise.ai/threats/klever-klever-go-unbounded-goroutine-spawn-in-directmessagehandler-8a95a76c"},{"cve":"CVE-2026-49343","cvss":5.9,"epss":0.0041,"slug":"cve-2026-49343-klever-io-klever-go-throttler-slot-leak-in-trie-account-data-sync","title":"Klever-io Klever-Go throttler slot leak in trie account-data sync","severity":"medium","exploited":false,"published_at":"2026-06-05T16:40:40+00:00","url":"https://junglewise.ai/threats/cve-2026-49343-klever-io-klever-go-throttler-slot-leak-in-trie-account-data-sync"},{"cve":"CVE-2026-47249","cvss":7.5,"epss":0.0049,"slug":"cve-2026-47249-klever-io-klever-go-resource-exhaustion-in-p2p-resolver","title":"Klever-io Klever-Go resource exhaustion in P2P resolver","severity":"high","exploited":false,"published_at":"2026-06-05T15:27:42+00:00","url":"https://junglewise.ai/threats/cve-2026-47249-klever-io-klever-go-resource-exhaustion-in-p2p-resolver"},{"cvss":7.5,"slug":"klever-go-resource-leak-in-p2p-multidatainterceptor-throttler-d4b2ec91","title":"Klever-Go resource leak in P2P MultiDataInterceptor throttler","severity":"high","exploited":false,"published_at":"2026-06-04T17:40:51+00:00","url":"https://junglewise.ai/threats/klever-go-resource-leak-in-p2p-multidatainterceptor-throttler-d4b2ec91"},{"cvss":3.1,"slug":"klever-go-p2p-multidatainterceptor-leaks-global-throttler-slots-on-906c953e","title":"Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS)","severity":"low","exploited":false,"published_at":"2026-06-04T17:40:51+00:00","url":"https://junglewise.ai/threats/klever-go-p2p-multidatainterceptor-leaks-global-throttler-slots-on-906c953e"},{"cve":"CVE-2026-44697","cvss":8.6,"epss":0.0046,"slug":"cve-2026-44697-klever-io-klever-go-denial-of-service-via-decompression-bomb","title":"Klever-io Klever-Go denial of service via decompression bomb","severity":"high","exploited":false,"published_at":"2026-05-29T18:17:09.697+00:00","url":"https://junglewise.ai/threats/cve-2026-44697-klever-io-klever-go-denial-of-service-via-decompression-bomb"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":2,"exploited":0,"vulnerabilities":4},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":6}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"},{"name":"github.com/juev/nebula-mesh (Go)","slug":"github-com-juev-nebula-mesh","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/github-com-juev-nebula-mesh"}],"technology":{"hub":true,"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://github.com/klever-io/klever-go","repo_url":"https://github.com/klever-io/klever-go","description":"A Go software development kit for interacting with the Klever blockchain network.","url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},"most_severe":[{"cve":"CVE-2026-54755","cvss":9.6,"epss":0.0056,"slug":"cve-2026-54755-klever-integer-overflow-in-split-royalty-validation-enables","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunc","severity":"critical","exploited":false,"published_at":"2026-08-28T20:18:17.67+00:00","url":"https://junglewise.ai/threats/cve-2026-54755-klever-integer-overflow-in-split-royalty-validation-enables"},{"cve":"CVE-2026-54754","cvss":9.6,"epss":0.0043,"slug":"cve-2026-54754-klever-marketplace-settlement-mints-klv-when-referral-and-royalty","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go","severity":"critical","exploited":false,"published_at":"2026-08-28T20:18:17.533+00:00","url":"https://junglewise.ai/threats/cve-2026-54754-klever-marketplace-settlement-mints-klv-when-referral-and-royalty"},{"cve":"CVE-2026-44697","cvss":8.6,"epss":0.0046,"slug":"cve-2026-44697-klever-io-klever-go-denial-of-service-via-decompression-bomb","title":"Klever-io Klever-Go denial of service via decompression bomb","severity":"high","exploited":false,"published_at":"2026-05-29T18:17:09.697+00:00","url":"https://junglewise.ai/threats/cve-2026-44697-klever-io-klever-go-denial-of-service-via-decompression-bomb"},{"cve":"CVE-2026-86064","cvss":8.6,"epss":0.004,"slug":"cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:19.96+00:00","url":"https://junglewise.ai/threats/cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration"},{"cve":"CVE-2026-47249","cvss":7.5,"epss":0.0049,"slug":"cve-2026-47249-klever-io-klever-go-resource-exhaustion-in-p2p-resolver","title":"Klever-io Klever-Go resource exhaustion in P2P resolver","severity":"high","exploited":false,"published_at":"2026-06-05T15:27:42+00:00","url":"https://junglewise.ai/threats/cve-2026-47249-klever-io-klever-go-resource-exhaustion-in-p2p-resolver"},{"cve":"CVE-2026-86065","cvss":7.5,"epss":0.0035,"slug":"cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/a","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:20.16+00:00","url":"https://junglewise.ai/threats/cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos"},{"cvss":7.5,"slug":"klever-io-klever-go-null-pointer-dereference-in-p2p-transaction-a0621e14","title":"Klever-io Klever-Go NULL pointer dereference in P2P transaction interceptor","severity":"high","exploited":false,"published_at":"2026-06-05T16:42:38+00:00","url":"https://junglewise.ai/threats/klever-io-klever-go-null-pointer-dereference-in-p2p-transaction-a0621e14"},{"cvss":7.5,"slug":"klever-klever-go-connection-exhaustion-in-rest-api-9b1a775a","title":"Klever klever-go connection exhaustion in REST API","severity":"high","exploited":false,"published_at":"2026-06-05T16:41:58+00:00","url":"https://junglewise.ai/threats/klever-klever-go-connection-exhaustion-in-rest-api-9b1a775a"},{"cvss":7.5,"slug":"klever-klever-go-unbounded-goroutine-spawn-in-directmessagehandler-8a95a76c","title":"Klever klever-go unbounded goroutine spawn in directMessageHandler","severity":"high","exploited":false,"published_at":"2026-06-05T16:41:23+00:00","url":"https://junglewise.ai/threats/klever-klever-go-unbounded-goroutine-spawn-in-directmessagehandler-8a95a76c"},{"cvss":7.5,"slug":"klever-go-resource-leak-in-p2p-multidatainterceptor-throttler-d4b2ec91","title":"Klever-Go resource leak in P2P MultiDataInterceptor throttler","severity":"high","exploited":false,"published_at":"2026-06-04T17:40:51+00:00","url":"https://junglewise.ai/threats/klever-go-resource-leak-in-p2p-multidatainterceptor-throttler-d4b2ec91"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}