<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T23:45:10.803143+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-377870</id>
    <title>EUVD-2026-377870</title>
    <updated>2026-10-06T23:45:10.851989+00:00</updated>
    <content>EUVD-2026-377870</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-377870"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-86065</id>
    <title>fkie_cve-2026-86065</title>
    <updated>2026-10-06T23:45:10.852028+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/api/websocket/routes.go accepts unauthenticated WebSocket clients with permissive origin handling, does not call SetReadLimit to bound message size, and has no live-connection cap. SocketHub.HandleClientInsertion also accepts an unbounded address list that grows addressSubscription, and client.loopIn continues reading without a size limit, allowing one client to grow subscription maps or many clients to retain goroutines, buffered channels, and descriptors. The global HTTP request throttler does not count upgraded live WebSocket connections. Because the REST and WebSocket API runs in the node process, memory or scheduler exhaustion can crash the node and interrupt P2P and consensus participation. This issue is fixed in version 1.7.20.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-86065"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4fwh-wrm6-97xm</id>
    <title>GHSA-4fwh-wrm6-97xm — Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -&gt; remote nod…</title>
    <updated>2026-10-06T23:45:10.852064+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/klever-io/klever-go</p>
<p>## Summary
The unauthenticated WebSocket endpoint `GET /subscribe` is registered `open: true` by default
(`config/node/api.yaml`) and lets a remote, unauthenticated client exhaust the node's memory and
goroutines. Because the REST API runs IN-PROCESS with the node — `network/api/api.go` `Start(...)`
ends with `ws.Run(kleverFacade.RestAPIInterface())` — exhausting/killing the API process takes down
the entire node, including its P2P and consensus participation. No API key, account, stake, or funds
are required.</p>
<p>Three compounding, independently-exploitable gaps stack on this one endpoint:</p>
<p>1. Permissive origin — `upgrader.CheckOrigin` always returns `true`
   (`network/api/websocket/routes.go`), so any web origin can complete the handshake.
2. No read-size limit — the connection never calls `conn.SetReadLimit(...)`. gorilla's default is
   UNLIMITED, so a single `conn.ReadJSON` (`processSubscription`) or `conn.ReadMessage`
   (`client.loopIn`) can be forced to allocate an arbitrarily large buffer from ONE frame.
3. No connection / fan-out cap — the gin global throttler (`simultaneousRequests: 100`) releases its
   slot as soon as `handleSubscribe` returns, which it does immediately after
   `go processSubscription(conn, hub)`. Live WebSocket connections are therefore NOT counted by it.
   There is no per-IP / per-connection / hub-level cap. Each accepted connection spawns 2 goroutines
   plus a 500-entry buffered channel, and `req.Addresses` has no length cap, so the hub's…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4fwh-wrm6-97xm"/>
  </entry>
</feed>
