Product
high
advisory
Authorization Bypass in Klever-Go KleverUpdateAccountPermission Built-in
1 rule 7 TTPsAn authorization flaw in the Klever-Go VM allows attackers to execute an account takeover by leveraging an incorrectly validated RecipientAddr parameter during indirect smart contract calls.
klever-go +2
blockchain
smart-contract
vulnerability
privilege-escalation
log-manipulation
unauthenticated-access
websocket-vulnerability
consensus-failure
+6
1r
7t
updated
medium
advisory
Integer Overflow in Klever Split-Royalty Validation Enables Unbounded Token Minting
1 TTPAn integer overflow vulnerability in the Klever node (klever-go) allows attackers to mint arbitrary amounts of KLV and other assets by bypassing split-royalty validation checks.
klever-go
integer-overflow
blockchain
financial-integrity
1t
medium
threat
Klever-Go MultiDataInterceptor Remote OOM via Compressed Payload
2 rules 2 TTPsKlever-Go's MultiDataInterceptor is vulnerable to a remote denial-of-service (DoS) attack. By sending a crafted compressed P2P payload, an unauthenticated attacker can trigger excessive memory allocation on the receiving node, leading to an out-of-memory (OOM) condition and potentially disrupting chain liveness.
klever-go
denial-of-service
decompression-bomb
2r
2t