Vulnerability in Klever-Go Semi-Fungible Token Processing by Klever
CVE-2026-55764
8.7HIGH
What is CVE-2026-55764?
Klever-Go, part of the Klever blockchain protocol, suffers from a vulnerability in its semi-fungible token handling. Prior to version 1.7.19, a mint-role holder could exploit a flaw in the SFTAddCirculation method, which allowed for the addition of tokens without proper checks for maximum supply limits and potential integer overflow. This oversight could lead to a situation where negative values were recorded in on-chain counters, inadvertently allowing the issuance of excessive token units beyond the designed limits. The issue was rectified in version 1.7.19 with the introduction of a consensus activation flag aimed at mitigating potential overflow and maintaining integrity in token management.
Affected Version(s)
klever-go < 1.7.19
