PT-2026-69155 · Klever-Go · Klever-Go
CVE-2026-58262
·
Published
2026-08-07
·
Updated
2026-08-12
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Klever-Go versions prior to 1.7.20
Description
Header signature verification incorrectly counts unused padding bits of the
PubKeysBitmap toward the two-thirds validator quorum. Because these padding bits do not correspond to any validator and are ignored by the BLS aggregate-signature check, a malicious or compromised block producer can manipulate them to simulate the required quorum with fewer genuine validator signatures than required. This allows nodes to accept headers as correctly signed without a real two-thirds quorum, which weakens consensus safety and undermines finality.Recommendations
Update to version 1.7.20.
Exploit
Fix
Insufficient Verification of Data Authenticity
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Klever-Go