Unrestricted Resource Consumption in Klever Blockchain Protocol Implementation
CVE-2026-55763

8.7HIGH

Key Information:

Vendor

Klever-io

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55763?

Klever-Go, the Go implementation of the Klever blockchain protocol, contains a vulnerability that can lead to unrestricted resource consumption during royalty transfers. In affected versions before 1.7.19, a configuration error allows a transfer with a 100% royalty split to execute, resulting in incorrect royalty distribution. This flaw permits a recipient to claim the full royalty amount without the sender incurring any costs, effectively enabling unregulated inflation of the KDA currency. Proper mitigation was introduced in version 1.7.19.

Affected Version(s)

klever-go < 1.7.19

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.