Denial-of-Service Vulnerability in Klever Blockchain Protocol by Klever
CVE-2026-44697
8.6HIGH
What is CVE-2026-44697?
Klever-Go, the Go version of the Klever blockchain protocol, contains a remote denial-of-service vulnerability that affects the Batch.Decompress function. Prior to version 1.7.17, this vulnerability allows malicious peers participating in a topic managed by MultiDataInterceptor to remotely allocate excessive memory on the receiving node utilizing a minimal gossip payload under 50 KiB. This can lead to an out-of-memory (OOM) condition, potentially causing a validating node to crash, which impacts the overall liveness of the blockchain network. This critical issue has been addressed in version 1.7.17.
Affected Version(s)
klever-go < 1.7.16
