<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 15:52:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-349760</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-349760</link>
      <description>EUVD-2026-349760</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-349760</guid>
    </item>
    <item>
      <title>fkie_cve-2026-52878</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52878</link>
      <description>&lt;p&gt;Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawData to decode to nil. Every transaction gossiped on the Klever-Go P2P network is decoded and validated synchronously inside the libp2p pubsub topic-validator callback, where txVersionChecker.CheckTxVersion dereferences tx.RawData.Version with no nil check. Because the libp2p pubsub callback, the underlying go-libp2p-pubsub validation worker, and Klever&amp;#39;s own network/p2p layer install no recover(), the panic propagates and crashes the entire node process. The attacker payload is a 3-byte protobuf message; no validator key, stake, funds, or on-chain account is required, and delivery aimed at enough of the BLS validator set can halt block production, resulting in a chain halt. This issue has been fixed in version 1.7.18.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawData to decode to nil. Every transaction gossiped on the Klever-Go P2P network is decoded and validated synchronously inside the libp2p pubsub topic-validator callback, where txVersionChecker.CheckTxVersion dereferences tx.RawData.Version with no nil check. Because the libp2p pubsub callback, the underlying go-libp2p-pubsub validation worker, and Klever&amp;#39;s own network/p2p layer install no recover(), the panic propagates and crashes the entire node process. The attacker payload is a 3-byte protobuf message; no validator key, stake, funds, or on-chain account is required, and delivery aimed at enough of the BLS validator set can halt block production, resulting in a chain halt. This issue has been fixed in version 1.7.18.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-52878</guid>
    </item>
    <item>
      <title>GHSA-rm5c-5x2p-48wr — Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionC…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rm5c-5x2p-48wr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/klever-io/klever-go&lt;/p&gt;
&lt;p&gt;## Summary
Every transaction gossiped on the klever-go P2P network is decoded and validated
synchronously inside the libp2p pubsub topic-validator callback. The validator
`txVersionChecker.CheckTxVersion` dereferences `tx.RawData.Version` with no nil
check. A protobuf `Transaction` whose embedded `RawData` sub-message is omitted
decodes to `RawData == nil`, so validating it triggers a nil-pointer panic.&lt;/p&gt;
&lt;p&gt;The libp2p pubsub callback, the underlying go-libp2p-pubsub validation worker, and
klever&amp;#39;s own `network/p2p` layer install no `recover()`, so the panic propagates and
crashes the entire node process. The attacker payload is a 3-byte protobuf message;
no validator key, stake, funds, or on-chain account is required. Aimed at enough of
the BLS validator set, repeated delivery halts block production (chain halt).&lt;/p&gt;
&lt;p&gt;## Affected component
- Root cause: `core/versioning/txVersionChecker.go:22`
- Reached via: `core/process/transaction/interceptedTransaction.go:203` (integrity) and `:154` (CheckValidity)
- Production tx-topic path: `core/process/interceptors/multiDataInterceptor.go:171` and `:223`
- Unprotected caller: `network/p2p/libp2p/netMessenger.go` `pubsubCallback` (no recover)
- Topic wiring: `core/process/factory/interceptorscontainer/baseInterceptorsContainerFactory.go` (`createOneTxInterceptor`)&lt;/p&gt;
&lt;p&gt;## Details
Synchronous validation path, no recovery at any frame:&lt;/p&gt;
&lt;p&gt;```
libp2p pubsubCallback                              network/p2p/libp2p/netMessenger.go  (no recover)
 -&amp;gt; Mult…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/klever-io/klever-go&lt;/p&gt;
&lt;p&gt;## Summary
Every transaction gossiped on the klever-go P2P network is decoded and validated
synchronously inside the libp2p pubsub topic-validator callback. The validator
`txVersionChecker.CheckTxVersion` dereferences `tx.RawData.Version` with no nil
check. A protobuf `Transaction` whose embedded `RawData` sub-message is omitted
decodes to `RawData == nil`, so validating it triggers a nil-pointer panic.&lt;/p&gt;
&lt;p&gt;The libp2p pubsub callback, the underlying go-libp2p-pubsub validation worker, and
klever&amp;#39;s own `network/p2p` layer install no `recover()`, so the panic propagates and
crashes the entire node process. The attacker payload is a 3-byte protobuf message;
no validator key, stake, funds, or on-chain account is required. Aimed at enough of
the BLS validator set, repeated delivery halts block production (chain halt).&lt;/p&gt;
&lt;p&gt;## Affected component
- Root cause: `core/versioning/txVersionChecker.go:22`
- Reached via: `core/process/transaction/interceptedTransaction.go:203` (integrity) and `:154` (CheckValidity)
- Production tx-topic path: `core/process/interceptors/multiDataInterceptor.go:171` and `:223`
- Unprotected caller: `network/p2p/libp2p/netMessenger.go` `pubsubCallback` (no recover)
- Topic wiring: `core/process/factory/interceptorscontainer/baseInterceptorsContainerFactory.go` (`createOneTxInterceptor`)&lt;/p&gt;
&lt;p&gt;## Details
Synchronous validation path, no recovery at any frame:&lt;/p&gt;
&lt;p&gt;```
libp2p pubsubCallback                              network/p2p/libp2p/netMessenger.go  (no recover)
 -&amp;gt; Mult…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rm5c-5x2p-48wr</guid>
    </item>
  </channel>
</rss>
