OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-86065

HIGH · CVSS 7.5 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Klever-Go implementation of the Klever blockchain protocol is vulnerable due to an unauthenticated WebSocket endpoint that allows unrestricted client connections and lacks proper message size limits. This can lead to memory or scheduler exhaustion, potentially crashing the node and disrupting peer-to-peer and consensus operations. Organizations using versions prior to 1.7.20 should prioritize updating to mitigate the risk of service interruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86065
Severity
HIGH
CVSS
7.5
EPSS
0.35%

Original NVD Description

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/api/websocket/routes.go accepts unauthenticated WebSocket clients with permissive origin handling, does not call SetReadLimit to bound message size, and has no live-connection cap. SocketHub.HandleClientInsertion also accepts an unbounded address list that grows addressSubscription, and client.loopIn continues reading without a size limit, allowing one client to grow subscription maps or many clients to retain goroutines, buffered channels, and descriptors. The global HTTP request throttler does not count upgraded live WebSocket connections. Because the REST and WebSocket API runs in the node process, memory or scheduler exhaustion can crash the node and interrupt P2P and consensus participation. This issue is fixed in version 1.7.20.