Signature Verification Vulnerability in Klever Blockchain Protocol by Klever
CVE-2026-58262

7.1HIGH

Key Information:

Vendor

Klever-io

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-58262?

The Klever-Go implementation of the Klever blockchain protocol contains a vulnerability that allows for the manipulation of header signature verification. Prior to version 1.7.20, the system incorrectly counted unused padding bits in the PubKeysBitmap towards the two-thirds validator quorum, despite these bits being irrelevant to the actual BLS aggregate-signature verification. This flaw enables malicious block producers to achieve the required quorum with fewer authentic validator signatures than mandated, thereby compromising consensus safety and undermining the finality of transactions within the network. The issue has been remedied in version 1.7.20.

Affected Version(s)

klever-go < 1.7.20

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.