CVE-2026-47249Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a compressed RequestDataType_HashArrayType direct request that is only 442 bytes on the wire but expands into 200,000 decoded hash entries inside the resolver path. The resolver's antiflood logic counts only a single logical message and the compressed wire size, and while Batch.Decompress() caps the decompressed byte size, it never limits the number of decoded repeated-field items. As a result, both TxResolver and TrieNodeResolver preallocate and iterate over the entire unchecked set of decoded hashes, causing remote memory and CPU amplification against any node that accepts P2P peer connections. This issue is fixed in version 1.7.18.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-08); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-08: 2Mentions · 2026-08-09: 1Patch / Workaround · 2026-08-09: 1Technical Details · 2026-08-08: 1Technical Details · 2026-08-09: 108-0808-09
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-082
Disclosure2
2026-08-091
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-47249 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplificati… https://www.cve.org/CVERecord?id=CVE-2026-47249

    Post summary

    The tweet announces CVE‑2026‑47249, detailing a hash-array amplification vulnerability in the P2P resolver logic of Klever-Go before version 1.7.18, but does not provide proofs, exploits, or indicate active exploitation.

    020301.3K
    58.1K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    💥 442-byte request can expand into 200,000 hashes CVE-2026-47249 affects Klever-Go before 1.7.18. A compressed P2P request of only about 442 bytes can expand internally into as many as 200,000 hash entries, amplifying CPU and memory consumption on remote nodes. ✅ Fixed in 1.7.18. 🔎 Source: GitHub / CVE / VulDB #BlockchainSecurity #DoS #Klever #CVE #CyberSecurity

    Post summary

    The post identifies CVE-2026-47249 as a DoS flaw in Klever-Go, provides specific technical details and notes the fix in version 1.7.18.

    0000048
    34 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-47249 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplificati… https://www.cve.org/CVERecord?id=CVE-2026-47249 ----- Traducción: CVE-2026-47249 Kle… http://infoflow.cloud`

    Post summary

    A new CVE-2026-47249 for Klever-Go is disclosed, highlighting a vulnerable P2P resolver logic before version 1.7.18, with no additional technical details or mitigations provided.

    0000044
    98 followersView on X

Explore more