{"schema_version":1,"title":"Klever Go SDK vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in Klever Go SDK: 6 in the last 7 days and 8 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86065, was published on 23 September 2026.","url":"https://junglewise.ai/threats/technologies/klever-go-sdk","json_url":"https://junglewise.ai/threats/technologies/klever-go-sdk.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/klever-go-sdk","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":8,"all_time":9,"critical":1,"exploited":0,"last_7_days":6,"last_30_days":8,"last_90_days":8,"last_365_days":9},"latest":[{"cve":"CVE-2026-86065","cvss":7.5,"epss":0.0035,"slug":"cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/a","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:20.16+00:00","url":"https://junglewise.ai/threats/cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos"},{"cve":"CVE-2026-86064","cvss":8.6,"epss":0.004,"slug":"cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:19.96+00:00","url":"https://junglewise.ai/threats/cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration"},{"cve":"CVE-2026-82409","cvss":4,"epss":0.0027,"slug":"cve-2026-82409-klever-go-elasticsearch-injection-via-account-name","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts pla","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.893+00:00","url":"https://junglewise.ai/threats/cve-2026-82409-klever-go-elasticsearch-injection-via-account-name"},{"cve":"CVE-2026-82407","cvss":4,"epss":0.0043,"slug":"cve-2026-82407-klever-go-bls-public-key-validation-bypass-in-validator","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.go Register and the r","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.707+00:00","url":"https://junglewise.ai/threats/cve-2026-82407-klever-go-bls-public-key-validation-bypass-in-validator"},{"cve":"CVE-2026-82406","cvss":4,"epss":0.0034,"slug":"cve-2026-82406-klever-go-marketplace-buy-missing-isclaimed-guard","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/mark","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.547+00:00","url":"https://junglewise.ai/threats/cve-2026-82406-klever-go-marketplace-buy-missing-isclaimed-guard"},{"cve":"CVE-2026-82405","cvss":4,"epss":0.0026,"slug":"cve-2026-82405-klever-go-account-takeover-via-authorization-bypass-in","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission built-in authorizes","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.37+00:00","url":"https://junglewise.ai/threats/cve-2026-82405-klever-go-account-takeover-via-authorization-bypass-in"},{"cve":"CVE-2026-55763","cvss":4,"epss":0.0051,"slug":"cve-2026-55763-klever-klever-go-percentage-transfer-royalty-zero-debit-in","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accou","severity":"high","exploited":false,"published_at":"2026-08-28T22:16:51.72+00:00","url":"https://junglewise.ai/threats/cve-2026-55763-klever-klever-go-percentage-transfer-royalty-zero-debit-in"},{"cve":"CVE-2026-54755","cvss":9.6,"epss":0.0056,"slug":"cve-2026-54755-klever-integer-overflow-in-split-royalty-validation-enables","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunc","severity":"critical","exploited":false,"published_at":"2026-08-28T20:18:17.67+00:00","url":"https://junglewise.ai/threats/cve-2026-54755-klever-integer-overflow-in-split-royalty-validation-enables"},{"cve":"CVE-2026-44697","cvss":8.6,"epss":0.0046,"slug":"cve-2026-44697-klever-io-klever-go-denial-of-service-via-decompression-bomb","title":"Klever-io Klever-Go denial of service via decompression bomb","severity":"high","exploited":false,"published_at":"2026-05-29T18:17:09.697+00:00","url":"https://junglewise.ai/threats/cve-2026-44697-klever-io-klever-go-denial-of-service-via-decompression-bomb"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":6}],"related":[],"technology":{"hub":true,"name":"Klever Go SDK","slug":"klever-go-sdk","vendor":{"name":"Klever","slug":"klever","url":"https://junglewise.ai/threats/vendors/klever"},"aliases":[],"category":"library","homepage":"https://klever.finance/","repo_url":"https://github.com/klever-io/klever-go","description":"Klever Go is a Go-based software development kit for interacting with the Klever blockchain network.","url":"https://junglewise.ai/threats/technologies/klever-go-sdk"},"most_severe":[{"cve":"CVE-2026-54755","cvss":9.6,"epss":0.0056,"slug":"cve-2026-54755-klever-integer-overflow-in-split-royalty-validation-enables","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunc","severity":"critical","exploited":false,"published_at":"2026-08-28T20:18:17.67+00:00","url":"https://junglewise.ai/threats/cve-2026-54755-klever-integer-overflow-in-split-royalty-validation-enables"},{"cve":"CVE-2026-44697","cvss":8.6,"epss":0.0046,"slug":"cve-2026-44697-klever-io-klever-go-denial-of-service-via-decompression-bomb","title":"Klever-io Klever-Go denial of service via decompression bomb","severity":"high","exploited":false,"published_at":"2026-05-29T18:17:09.697+00:00","url":"https://junglewise.ai/threats/cve-2026-44697-klever-io-klever-go-denial-of-service-via-decompression-bomb"},{"cve":"CVE-2026-86064","cvss":8.6,"epss":0.004,"slug":"cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:19.96+00:00","url":"https://junglewise.ai/threats/cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration"},{"cve":"CVE-2026-86065","cvss":7.5,"epss":0.0035,"slug":"cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/a","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:20.16+00:00","url":"https://junglewise.ai/threats/cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos"},{"cve":"CVE-2026-55763","cvss":4,"epss":0.0051,"slug":"cve-2026-55763-klever-klever-go-percentage-transfer-royalty-zero-debit-in","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accou","severity":"high","exploited":false,"published_at":"2026-08-28T22:16:51.72+00:00","url":"https://junglewise.ai/threats/cve-2026-55763-klever-klever-go-percentage-transfer-royalty-zero-debit-in"},{"cve":"CVE-2026-82407","cvss":4,"epss":0.0043,"slug":"cve-2026-82407-klever-go-bls-public-key-validation-bypass-in-validator","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.go Register and the r","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.707+00:00","url":"https://junglewise.ai/threats/cve-2026-82407-klever-go-bls-public-key-validation-bypass-in-validator"},{"cve":"CVE-2026-82406","cvss":4,"epss":0.0034,"slug":"cve-2026-82406-klever-go-marketplace-buy-missing-isclaimed-guard","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/mark","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.547+00:00","url":"https://junglewise.ai/threats/cve-2026-82406-klever-go-marketplace-buy-missing-isclaimed-guard"},{"cve":"CVE-2026-82409","cvss":4,"epss":0.0027,"slug":"cve-2026-82409-klever-go-elasticsearch-injection-via-account-name","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts pla","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.893+00:00","url":"https://junglewise.ai/threats/cve-2026-82409-klever-go-elasticsearch-injection-via-account-name"},{"cve":"CVE-2026-82405","cvss":4,"epss":0.0026,"slug":"cve-2026-82405-klever-go-account-takeover-via-authorization-bypass-in","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission built-in authorizes","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.37+00:00","url":"https://junglewise.ai/threats/cve-2026-82405-klever-go-account-takeover-via-authorization-bypass-in"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}