top of page
perceptive_background_267k.jpg

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can c…

Published:

28 August 2026 at 00:00:00

Alert date:

28 August 2026 at 23:18:32

Source:

nvd.nist.gov

Click to open the original link from this advisory

Emerging Technologies, Supply Chain & Dependencies

CVE-2026-54755 affects Klever-Go, the Go implementation of the Klever blockchain protocol, in versions prior to 1.7.19. The vulnerability exists in the split-royalty field decoding logic where values exceeding core.HundredPercent are accepted without proper validation. Integer overflow in uint32 accumulators allows crafted values (e.g., two 0x80000000 entries) to wrap the validation sum to zero, bypassing the CheckValid100Params check. Affected royalty payout paths in accounts, market, and ITO modules then credit oversized split amounts and silently discard negative remainders. This allows attackers to create unbacked KLV or other blockchain assets through ordinary asset transfers, marketplace purchases, or ITO purchases. The vulnerability represents an arbitrary token minting risk with significant financial implications for the blockchain ecosystem. The issue has been patched in version 1.7.19.

Technical details

Mitigation steps:

Affected products:

Klever-Go
Klever blockchain protocol

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page