目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-49343— Klever 资源管理错误漏洞

CVSS 5.9 · Medium EPSS 0.26% · P18

可能的 ATT&CK 技术 1AI

T1496 · Resource Hijacking

影响版本矩阵 1

厂商产品版本范围状态
klever-ioklever-go< 1.7.18affected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-49343 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS
来源: CVE Program / CVE List V5
Vulnerability Description
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a resource-exhaustion flaw that leaks bounded throttler slots on error paths. In syncDataTrie() (in both userAccountsSyncer.go and kappAccountsSyncer.go), StartProcessing() reserves a slot from the NumGoRoutinesThrottler, but the corresponding EndProcessing() is only called on the success path and on the duplicate-root early return. As a result, any error from trie.NewTrie(), trie.NewTrieSyncer(), or trieSyncer.StartSyncing() (including the network-dependent timeout path) permanently consumes one slot for the lifetime of the throttler. An attacker who can repeatedly cause trie-node sync failures or timeouts during bootstrap can exhaust the bounded throttler, after which further account-data trie syncs stop making progress and SyncAccounts() returns a timeout. Because epoch bootstrap in syncUserAccountsState() and syncKappAccountsState() aborts on any such error, this causes bootstrap to fail, a core availability issue affecting fresh, restarting, or resyncing nodes and validators. This issue is fixed in version 1.7.18.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
来源: CVE Program / CVE List V5
Vulnerability Title
Klever 资源管理错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Klever是Klever组织的一个高性能区块链网络,专为去中心化应用、资产管理和智能合约执行而设计。 Klever 1.7.18之前版本存在资源管理错误漏洞,该漏洞源于账户数据trie同步器在错误路径上泄漏有界throttler槽,导致资源耗尽,可能造成bootstrap失败,影响节点和验证者的可用性。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
klever-ioklever-go < 1.7.18 -

二、漏洞 CVE-2026-49343 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-49343 的情报信息

登录查看更多情报信息。

CVE-2026-49343 厂商安全公告 (1)

CVE-2026-49343 其他参考 (1)

同批安全公告 · klever-io · 2026-08-07 · 共 6 条

CVE-2026-528787.5 HIGHKlever 异常处理不当漏洞
CVE-2026-528797.5 HIGHKlever 资源管理错误漏洞
CVE-2026-472497.5 HIGHKlever 资源管理错误漏洞
CVE-2026-528807.5 HIGHKlever 资源管理错误漏洞
CVE-2026-582627.1 HIGHKlever 输入验证错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-49343

暂无评论


发表评论