Vulnerabilities
Last updated 2 hours ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller | High Risk 8.0 | 8 days ago | 6 hours ago |
|
|
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace | High Risk 8.0 | 8 days ago | 6 hours ago |
|
|
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS | High Risk 8.0 | 8 days ago | 6 hours ago |
|
|
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery | High Risk 8.0 | 8 days ago | 6 hours ago |
|
|
Klever-Go: /log controls global node logging | High Risk 8.6 | 8 days ago | 6 hours ago |
|
|
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS) | High Risk 7.5 | 8 days ago | 6 hours ago |
|
|
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS) in github.com/klever-io/klever-go | Unknown | 7 hours ago | 7 hours ago |
|
|
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery in github.com/klever-io/klever-go | Unknown | 7 hours ago | 7 hours ago |
|
|
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS in github.com/klever-io/klever-go | Unknown | 7 hours ago | 7 hours ago |
|
|
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller in github.com/klever-io/klever-go | Unknown | 7 hours ago | 7 hours ago |
|
|
Klever-Go: /log controls global node logging in github.com/klever-io/klever-go | Unknown | 7 hours ago | 7 hours ago |
|
|
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace in github.com/klever-io/klever-go | Unknown | 7 hours ago | 7 hours ago |
|
|
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) | Critical 9.6 | 1 month ago | 29 days ago |
|
|
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply | High Risk 8.0 | 1 month ago | 29 days ago |
|
|
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go | Unknown | 29 days ago | 29 days ago |
|
|
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go | Unknown | 29 days ago | 29 days ago |
|
|
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) | Critical 9.6 | 1 month ago | 29 days ago |
|
|
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits | High Risk 8.0 | 1 month ago | 29 days ago |
|
|
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go | Unknown | 29 days ago | 29 days ago |
|
|
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go | Unknown | 29 days ago | 29 days ago |
|
|
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload | High Risk 8.6 | 4 months ago | 2 months ago |
|
|
klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS | High Risk 7.5 | 3 months ago | 3 months ago |
|
|
Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt | High Risk 7.5 | 3 months ago | 3 months ago |
|
|
klever-go: REST API slow-header connection exhaustion via Gin Engine.Run | High Risk 7.5 | 3 months ago | 3 months ago |
|
|
Klever-Go KVM read-only execution can commit contract delete and upgrade side effects | Medium Risk 6.3 | 4 months ago | 3 months ago |
|
|
Klever-Go KVM: Hash-array amplification in P2P resolver request handling | High Risk 7.5 | 3 months ago | 3 months ago |
|
|
Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt in github.com/klever-io/klever-go | Unknown | 3 months ago | 3 months ago |
|
|
Klever-Go KVM: Hash-array amplification in P2P resolver request handling in github.com/klever-io/klever-go | Unknown | 3 months ago | 3 months ago |
|
|
klever-go: REST API slow-header connection exhaustion via Gin Engine.Run in github.com/klever-io/klever-go | Unknown | 3 months ago | 3 months ago |
|
|
Klever-Go KVM read-only execution can commit contract delete and upgrade side effects in github.com/klever-io/klever-go | Unknown | 3 months ago | 3 months ago |
|
|
klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS in github.com/klever-io/klever-go | Unknown | 3 months ago | 3 months ago |
|
|
Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS) | High Risk 7.5 | 3 months ago | 3 months ago |
|
|
Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS | Medium Risk 5.9 | 3 months ago | 3 months ago |
|
|
Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS in github.com/klever-io/klever-go | Unknown | 3 months ago | 3 months ago |
|
|
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload in github.com/klever-io/klever-go | Unknown | 3 months ago | 3 months ago |
|
|
Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS) in github.com/klever-io/klever-go | Unknown | 3 months ago | 3 months ago |
Page 1