CVE-2026-82406High· 7.1▾ TwilightKlever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/market.go Buy does not check IsClaimed before accepting a bid. A seller can use the Claim seller-acce…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/market.go Buy does not check IsClaimed before accepting a bid. A seller can use the Claim seller-accept branch to settle a resting-bid auction while leaving the claimed order loadable with a future EndTime and stale CurrentBid and CurrentBidder values. A later bidder can submit a higher bid, be debited, and cause the previous bidder to receive a refund even though the NFT has already been delivered. Because Claim and CancelOrder reject the later bidder when IsClaimed is true, the later bidder cannot obtain the NFT or recover the funds. This issue is fixed in version 1.7.20.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/klever-io/klever-go <= 1.7.19Patched in:
github.com/klever-io/klever-go 1.7.20Connected by shared product, vendor, weakness, or advisory.
CVE-2026-82407High· 7.0Klever-Go is the Go implementation of the Klever blockchain protocol
CVE-2026-82409High· 8.4Klever-Go is the Go implementation of the Klever blockchain protocol
CVE-2026-86064High· 8.6Klever-Go is the Go implementation of the Klever blockchain protocol
CVE-2026-86065High· 7.5Klever-Go is the Go implementation of the Klever blockchain protocol
CVE-2026-82405High· 8.7Klever-Go is the Go implementation of the Klever blockchain protocol
CVE-2026-49343Medium· 5.9Klever-Go is the Go implementation of the Klever blockchain protocol