Threat Advisory

Klever-Go Validator Registration Accepts Unvalidated BLS Public Key

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-82407 with a CVSS score of 7.0 is a vulnerability in Klever-Go's validator registration that accepts an unvalidated BLS public key, leading to a consensus liveness DoS attack. Affected versions are github.: <= 1.7.19. This flaw allows attackers to submit a malformed key, which deserializes deterministically and fails verification on the honest leader's node, causing every in-group node to call SetSlotCanceled(true) at slot start. The impact is sustained liveness degradation, with one eligible bad-key validator poisoning roughly a groupSize / eligibleSet fraction of rounds. In small or early-stage networks, this results in a full chain halt. The vulnerability can be exploited by staking the minimum to register a validator and submitting an arbitrary 96-byte BLSPublicKey that is not a valid G2 point, allowing permissionless and repeatable attacks with no fork flag gates.

RECOMMENDATION:

We recommend you to update klever-go to version 1.7.20.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-82407 with a CVSS score of 7.0 is a vulnerability in Klever-Go's validator registration that accepts an unvalidated BLS public key, leading to a consensus liveness DoS attack. Affected versions are github.: <= 1.7.19. This flaw allows attackers to submit a malformed key, which deserializes deterministically and fails verification on the honest leader's node, causing every in-group node to call SetSlotCanceled(true) at slot start. The impact is sustained liveness degradation, with one eligible bad-key validator poisoning roughly a groupSize / eligibleSet fraction of rounds. In small or early-stage networks, this results in a full chain halt. The vulnerability can be exploited by staking the minimum to register a validator and submitting an arbitrary 96-byte BLSPublicKey that is not a valid G2 point, allowing permissionless and repeatable attacks with no fork flag gates.

RECOMMENDATION:

We recommend you to update klever-go to version 1.7.20.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu