Klever-Go 是 Klever 区块链协议的 Go 语言实现。在 1.7.19 之前, 中的 函数在拆分循环之后以及 提前返回之后才调用 。由于 仅在 时才拒绝处理,一个 (即 100%)的有效拆分会恰好消耗整个版税池的 100%,将 置为零,并在从源账户扣款之前就提前返回。结果,拆分的接收方收到了全额的 ,而发送方未支付任何费用,且供应量计数器未更新,从而导致被转移的 KDA 出现无限制的非账本内通胀。要触发此问题,KDA 持有者需配置一个包含 100% 拆分的 版税,此后任何持有者转移该资产即会触发铸造。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54754 | 9.6 CRITICAL | Klever-Go: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (ne |
| CVE-2026-54755 | 9.6 CRITICAL | Klever-Go: Integer overflow in split-royalty validation enables unbounded minting of KLV ( |
| CVE-2026-55764 | 8.7 HIGH | Klever-Go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply |
No comments yet