CVE-2026-47249
Klever · Klever-Go
Klever-Go contains an uncontrolled resource consumption vulnerability that can be exploited by unauthenticated remote attackers to cause a denial of service.
Executive summary
A high-severity uncontrolled resource consumption vulnerability in Klever-Go versions prior to 1.7.18 enables remote denial of service attacks.
Vulnerability
This is an uncontrolled resource consumption vulnerability (CWE-400) within the Klever-Go protocol implementation. An unauthenticated remote attacker can trigger this condition to consume excessive system resources and crash the node.
Business impact
The potential for service disruption is significant, as the vulnerability allows for a denial of service attack without requiring authentication. With a CVSS score of 7.5, this vulnerability represents a substantial threat to the availability of blockchain infrastructure, potentially impacting transaction processing and node uptime.
Remediation
Immediate Action: Update to Klever-Go version 1.7.18 or later to resolve the underlying resource management flaw.
Proactive Monitoring: Monitor logs for patterns indicative of resource exhaustion attacks, such as repeated connection attempts or unusually large data payloads.
Compensating Controls: Deploy network-level traffic filtering to mitigate the impact of potential resource-exhaustion traffic while the update process is underway.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Immediate application of the vendor update to version 1.7.18 is required to secure the node against remote exploitation. Security teams should treat this as a high-priority task to prevent potential service outages.