Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-54754: Klever-Go before 1.7.19 may create unbacked tokens
CVE-2026-54754 · published 1 day ago
Summary
If you run Klever-Go version earlier than 1.7.19, a seller can manipulate referral and royalty settings so the system pays out more tokens than were actually bought. This can inflate the token supply and damage the integrity of the marketplace. Upgrade to version 1.7.19 or later to stop the problem.
What to do
- Update klever-io github.com/klever-io/klever-go to version 1.7.19.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Go | klever-io | github.com/klever-io/klever-go |
< 1.7.19 Fix: upgrade to 1.7.19
|
| – | klever-io | klever-go | < 1.7.19 |
Original advisory text
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go
References
Severity
9.6
Critical
CVSS 3.1: 9.6 (OSV)
Exploitation
EPSS <1%
Type
CWE-191Integer Underflow (Wrap or Wraparound)
CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition
CWE-682Incorrect Calculation
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen28 Aug 2026
Sources
GHSA-p7gw-2pcp-5pf8 · OSV
CVE-2026-54754 · NVD
CVE-2026-54754 · MITRE
GO-2026-6315 · OSV
GHSA-p7gw-2pcp-5pf8 · GHSA
Monitor software like this
Free during beta