Signature Verification Vulnerability in Klever Blockchain Protocol by Klever
CVE-2026-58262
7.1HIGH
What is CVE-2026-58262?
The Klever-Go implementation of the Klever blockchain protocol contains a vulnerability that allows for the manipulation of header signature verification. Prior to version 1.7.20, the system incorrectly counted unused padding bits in the PubKeysBitmap towards the two-thirds validator quorum, despite these bits being irrelevant to the actual BLS aggregate-signature verification. This flaw enables malicious block producers to achieve the required quorum with fewer authentic validator signatures than mandated, thereby compromising consensus safety and undermining the finality of transactions within the network. The issue has been remedied in version 1.7.20.
Affected Version(s)
klever-go < 1.7.20
