VulnSea

klever-io has 6 CVEs on record. Disclosure cadence is accelerating: 5 in the last 90 days against 1 in the 90 before. The busiest recent month was August 2026 with 5. The median CVSS is 9.1 (critical), with 2 rated critical. None have a confirmed exploitation report. Most affected products: github.com/klever-io/klever-go (5), klever-go (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.1
Publish → KEV
Last 90 days
5 prev 1

Products

  • github.com/klever-io/klever-go 5
  • klever-go 1
6
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

klever-io vulnerabilities

CVEs affecting klever-io, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-55764High
3w ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role holder to bypass a finite per-nonce MaxSupply on the semi-fungible token add-quantity path. In core/kapp/systemAccount/sy…

Twilightklever-io · github.com/klever-io/klever-goEPSS 0.32%via NVD
CVE-2026-55763High
3w ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the split loop and after the royaltiesToPay <= 0 early…

Twilightklever-io · github.com/klever-io/klever-goEPSS 0.30%via NVD
CVE-2026-54754Critical· 9.6
3w ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPer…

Midnightklever-io · github.com/klever-io/klever-goEPSS 0.30%via NVD
CVE-2026-54755Critical· 9.6
3w ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go a…

Midnightklever-io · github.com/klever-io/klever-goEPSS 0.39%via NVD
CVE-2026-49343Medium· 5.9PoC
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a resource-exhaustion flaw that leaks bounded throttler slots on error paths. In syncDataT…

Twilightklever-io · klever-goEPSS 0.32%via NVD
CVE-2026-44697High· 8.6
4mo ago

Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload

Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload

Twilightklever-io · github.com/klever-io/klever-goEPSS 0.38%via OSV
klever-io vulnerabilities (CVEs) · VulnSea