CVE-2026-82407 with a CVSS score of 7.0 is a vulnerability in Klever-Go's validator registration that accepts an unvalidated BLS public key, leading to a consensus liveness DoS attack. Affected versions are github.: <= 1.7.19. This flaw allows attackers to submit a malformed key, which deserializes deterministically and fails verification on the honest leader's node, causing every in-group node to call SetSlotCanceled(true) at slot start. The impact is sustained liveness degradation, with one eligible bad-key validator poisoning roughly a groupSize / eligibleSet fraction of rounds. In small or early-stage networks, this results in a full chain halt. The vulnerability can be exploited by staking the minimum to register a validator and submitting an arbitrary 96-byte BLSPublicKey that is not a valid G2 point, allowing permissionless and repeatable attacks with no fork flag gates.
We recommend you to update klever-go to version 1.7.20.[/subscribe_to_unlock_form]
CVE-2026-82407 with a CVSS score of 7.0 is a vulnerability in Klever-Go's validator registration that accepts an unvalidated BLS public key, leading to a consensus liveness DoS attack. Affected versions are github.: <= 1.7.19. This flaw allows attackers to submit a malformed key, which deserializes deterministically and fails verification on the honest leader's node, causing every in-group node to call SetSlotCanceled(true) at slot start. The impact is sustained liveness degradation, with one eligible bad-key validator poisoning roughly a groupSize / eligibleSet fraction of rounds. In small or early-stage networks, this results in a full chain halt. The vulnerability can be exploited by staking the minimum to register a validator and submitting an arbitrary 96-byte BLSPublicKey that is not a valid G2 point, allowing permissionless and repeatable attacks with no fork flag gates.
We recommend you to update klever-go to version 1.7.20.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]