CVE-2026-52879
Klever · Klever-Go
Klever-Go is vulnerable to uncontrolled resource consumption, which can be triggered by unauthenticated actors to cause a denial of service.
Executive summary
Uncontrolled resource allocation in Klever-Go versions 1.7.14 through 1.7.17 allows unauthenticated attackers to cause a denial of service via resource exhaustion.
Vulnerability
This vulnerability involves uncontrolled resource consumption (CWE-400) and improper allocation limits (CWE-770). The flaw is remotely exploitable by an unauthenticated attacker, allowing them to exhaust system memory or CPU.
Business impact
Exploitation of this vulnerability leads to a denial of service condition, which can halt blockchain node operations. The CVSS score of 7.5 reflects the high severity of this risk, as it can be leveraged to disrupt network consensus or node synchronization, leading to operational downtime.
Remediation
Immediate Action: Upgrade to Klever-Go version 1.7.18 or later to apply the necessary resource management controls.
Proactive Monitoring: Review system resource utilization metrics, specifically looking for abnormal spikes in memory or CPU usage that correlate with incoming network traffic.
Compensating Controls: Utilize load balancers or firewalls to limit the volume of incoming requests, which can help prevent resource exhaustion attacks.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations should update their Klever-Go environments to version 1.7.18 immediately to mitigate the risk of denial of service. Timely patching is critical to ensuring the ongoing availability and integrity of the protocol.