PT-2026-69155 · Klever-Go · Klever-Go

CVE-2026-58262

·

Published

2026-08-07

·

Updated

2026-08-12

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Klever-Go versions prior to 1.7.20
Description Header signature verification incorrectly counts unused padding bits of the PubKeysBitmap toward the two-thirds validator quorum. Because these padding bits do not correspond to any validator and are ignored by the BLS aggregate-signature check, a malicious or compromised block producer can manipulate them to simulate the required quorum with fewer genuine validator signatures than required. This allows nodes to accept headers as correctly signed without a real two-thirds quorum, which weakens consensus safety and undermines finality.
Recommendations Update to version 1.7.20.

Exploit

Fix

Insufficient Verification of Data Authenticity

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58262
GHSA-F9H7-4MMQ-VGCQ

Affected Products

Klever-Go