Vulnerability Description
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/kapp/kda/trigger.go sum those values in uint32 accumulators. Crafted values such as two 0x80000000 entries wrap the validation sum to zero and pass CheckValid100Params. Royalty payout paths in core/kapp/accounts/accounts.go, core/kapp/market/market.go, and core/kapp/ito/ito.go then credit each oversized split amount and silently discard a negative remainder, allowing ordinary asset transfers, marketplace purchases, or ITO purchases to create unbacked KLV or other assets. This issue is fixed in version 1.7.19.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/klever-io/klever-go/commit/8bcc600b0ac88070740c63c7ce1c8a968d
- https://github.com/klever-io/klever-go/releases/tag/v1.7.19
- https://github.com/klever-io/klever-go/security/advisories/GHSA-cgc5-v3f2-8m2v
FAQ
What is CVE-2026-54755?
CVE-2026-54755 is a vulnerability with a CVSS score of 9.6 (CRITICAL). Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredP...
How severe is CVE-2026-54755?
CVE-2026-54755 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-54755?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.