


Perceptive Security
SOC/SIEM Consultancy

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can c…
Published:
28 August 2026 at 00:00:00
Alert date:
28 August 2026 at 23:18:32
Source:
nvd.nist.gov
Emerging Technologies, Supply Chain & Dependencies
CVE-2026-54755 affects Klever-Go, the Go implementation of the Klever blockchain protocol, in versions prior to 1.7.19. The vulnerability exists in the split-royalty field decoding logic where values exceeding core.HundredPercent are accepted without proper validation. Integer overflow in uint32 accumulators allows crafted values (e.g., two 0x80000000 entries) to wrap the validation sum to zero, bypassing the CheckValid100Params check. Affected royalty payout paths in accounts, market, and ITO modules then credit oversized split amounts and silently discard negative remainders. This allows attackers to create unbacked KLV or other blockchain assets through ordinary asset transfers, marketplace purchases, or ITO purchases. The vulnerability represents an arbitrary token minting risk with significant financial implications for the blockchain ecosystem. The issue has been patched in version 1.7.19.
Technical details
Mitigation steps:
Affected products:
Klever-Go
Klever blockchain protocol
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54755
https://github.com/klever-io/klever-go/commit/8bcc600b0ac88070740c63c7ce1c8a968dd85251
https://github.com/klever-io/klever-go/releases/tag/v1.7.19
https://github.com/klever-io/klever-go/security/advisories/GHSA-cgc5-v3f2-8m2v
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
