


Perceptive Security
SOC/SIEM Consultancy

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decomp…
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 19:07:03
Source:
nvd.nist.gov
Emerging Technologies, Network Infrastructure
A critical denial-of-service vulnerability in Klever-Go blockchain protocol implementation prior to version 1.7.17. The vulnerability exists in the Batch.Decompress function and allows remote, unauthenticated attackers to cause memory exhaustion. Attackers can send small gossip payloads (under 50 KiB) that force receiving nodes to allocate multi-gigabyte heaps. A single malicious packet can trigger out-of-memory conditions on validators with standard memory configurations. Fleet-wide exploitation can compromise entire blockchain network liveness. The vulnerability has been patched in version 1.7.17.
Technical details
Mitigation steps:
Affected products:
Klever-Go
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44697
https://github.com/klever-io/klever-go/security/advisories/GHSA-87m7-qffr-542v
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
