Vulnerability in Klever-Go Semi-Fungible Token Processing by Klever
CVE-2026-55764

8.7HIGH

Key Information:

Vendor

Klever-io

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55764?

Klever-Go, part of the Klever blockchain protocol, suffers from a vulnerability in its semi-fungible token handling. Prior to version 1.7.19, a mint-role holder could exploit a flaw in the SFTAddCirculation method, which allowed for the addition of tokens without proper checks for maximum supply limits and potential integer overflow. This oversight could lead to a situation where negative values were recorded in on-chain counters, inadvertently allowing the issuance of excessive token units beyond the designed limits. The issue was rectified in version 1.7.19 with the introduction of a consensus activation flag aimed at mitigating potential overflow and maintaining integrity in token management.

Affected Version(s)

klever-go < 1.7.19

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.