PT-2026-97526 · Klever-Go · Klever-Go

CVE-2026-82407

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions Klever-Go versions prior to 1.7.20
Description Klever-Go, the Go implementation of the Klever blockchain protocol, fails to perform curve, prime-order subgroup, or nonzero validation on submitted BLSPublicKey during runtime validator registration and update paths. This occurs because the Register function in core/kapp/validators/validators.go and the runtime validator update path do not enforce these checks, unlike the genesis validation path which uses CheckPublicKeyValid().
An attacker can register a validator with a malformed 96-byte BLSPublicKey that is not a valid G2 point. When this validator is selected for a consensus group, the MultiSigner.Reset() function and the signature verification creation path (specifically the Create() function) fail to deserialize the group key. This results in the slot being canceled and the round being missed. Depending on the network size, this can lead to sustained throughput degradation or a complete chain halt if the consensus group equals the eligible validator set.
Recommendations Update to version 1.7.20. As a temporary mitigation, restrict the registration of new validators or the updating of validator configurations until the update is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82407
GHSA-9WH6-9HQ7-9688

Affected Products

Klever-Go