QSearchQSearch

CVE-2026-44697

8.6 HIGH

Klever-Go is the Go implementation of the Klever blockchain protocol

Published: 2026-05-29 · Last updated: 2026-06-02

Severity and scoring

CVSS
8.6 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE
CWE-409, CWE-770

Description

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that participates in a topic served by MultiDataInterceptor to allocate multi-gigabyte heaps on the receiving node from a sub-50 KiB gossip payload. A single packet is sufficient to OOM-kill a validator with conventional memory provisioning. Fleet-wide application affects chain liveness. This vulnerability is fixed in 1.7.17.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-53460 ImageMagick is free and open-source software used for editing and manipulating digital images (7.5 HIGH)
  • CVE-2026-46702 Russh is a Rust SSH client & server library (7.5 HIGH)
  • CVE-2026-46673 Russh is a Rust SSH client & server library (7.5 HIGH)
  • CVE-2026-45031 ImageMagick is free and open-source software used for editing and manipulating digital images (5.3 MEDIUM)
  • CVE-2026-10740 Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a... (5.3 MEDIUM)