klever-io has 6 CVEs on record. Disclosure cadence is accelerating: 5 in the last 90 days against 1 in the 90 before. The busiest recent month was August 2026 with 5. The median CVSS is 9.1 (critical), with 2 rated critical. None have a confirmed exploitation report. Most affected products: github.com/klever-io/klever-go (5), klever-go (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.1
- Publish → KEV
- —
- Last 90 days
- 5 prev 1
Products
- github.com/klever-io/klever-go 5
- klever-go 1
Worst active — by depth score
CVE-2026-54755Critical· 9.6Klever-Go is the Go implementation of the Klever blockchain protocol53CVE-2026-54754Critical· 9.6Klever-Go is the Go implementation of the Klever blockchain protocol53CVE-2026-44697High· 8.6Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload47CVE-2026-49343Medium· 5.9Klever-Go is the Go implementation of the Klever blockchain protocol45CVE-2026-55764HighKlever-Go is the Go implementation of the Klever blockchain protocol41
klever-io vulnerabilities
CVEs affecting klever-io, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-55764HighKlever-Go is the Go implementation of the Klever blockchain protocol
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role holder to bypass a finite per-nonce MaxSupply on the semi-fungible token add-quantity path. In core/kapp/systemAccount/sy…
CVE-2026-55763HighKlever-Go is the Go implementation of the Klever blockchain protocol
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the split loop and after the royaltiesToPay <= 0 early…
CVE-2026-54754Critical· 9.6Klever-Go is the Go implementation of the Klever blockchain protocol
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPer…
CVE-2026-54755Critical· 9.6Klever-Go is the Go implementation of the Klever blockchain protocol
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go a…
CVE-2026-49343Medium· 5.9PoCKlever-Go is the Go implementation of the Klever blockchain protocol
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a resource-exhaustion flaw that leaks bounded throttler slots on error paths. In syncDataT…
CVE-2026-44697High· 8.6Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload