PT-2026-97530 · Klever-Go · Klever-Go
CVE-2026-86065
·
Published
2026-09-23
·
Updated
2026-09-29
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Klever-Go versions prior to 1.7.20
Description
The 'GET /subscribe' endpoint accepts unauthenticated WebSocket clients with permissive origin handling and lacks a live-connection cap or a call to
SetReadLimit to bound message size. Additionally, the SocketHub.HandleClientInsertion() function accepts an unbounded address list that increases the size of addressSubscription, while client.loopIn() continues reading without a size limit. This allows a single client to expand subscription maps or multiple clients to consume goroutines, buffered channels, and descriptors. Since the global HTTP request throttler does not account for upgraded live WebSocket connections and the API runs within the node process, memory or scheduler exhaustion can crash the node, interrupting P2P and consensus participation.Recommendations
Update to version 1.7.20.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Klever-Go