-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0174 ============================================================ Advisory-ID: 0xCERT-2026-0174 Severity: High Published: 2026-09-23T20:17:16.547Z Updated: 2026-10-08T22:46:36.661Z Chains: n/a URL: https://www.0xcert.com/advisory/0xCERT-2026-0174 Title: CVE-2026-82406: Klever-Go Summary - ------- Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/market.go Buy does not check IsClaimed before accepting a bid. A seller can use the Claim seller-accept branch to settle a resting-bid auction while leaving the claimed order loadable with a future EndTime and stale CurrentBid and CurrentBidder values. A later bidder can submit a higher bid, be debited, and cause the previous bidder to receive a refund even though the NFT has already been delivered. Because Claim and CancelOrder reject the later bidder when I… Details - ------- Summary Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/market.go Buy does not check IsClaimed before accepting a bid. A seller can use the Claim seller-accept branch to settle a resting-bid auction while leaving the claimed order loadable with a future EndTime and stale CurrentBid and CurrentBidder values. A later bidder can submit a higher bid, be debited, and cause the previous bidder to receive a refund even though the NFT has already been delivered. Because Claim and CancelOrder reject the later bidder when IsClaimed is true, the later bidder cannot obtain the NFT or recover the funds. This issue is fixed in version 1.7.20. Severity High (CVSS 7.1), as scored by NVD. Weakness - - CWE-841 Recommended actions - - Check whether you run or depend on the affected component and version - - Apply the vendor's fix or mitigation from the references below Source & attribution This 0xCERT advisory summarises CVE-2026-82406 from the U.S. National Vulnerability Database: https://nvd.nist.gov/vuln/detail/CVE-2026-82406. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://nvd.nist.gov/vuln/detail/CVE-2026-82406 - - https://github.com/klever-io/klever-go/commit/063bb3ed98f9a84a4b1f7286680613a5fc3c91b2 - - https://github.com/klever-io/klever-go/pull/16 - - https://github.com/klever-io/klever-go/releases/tag/v1.7.20 - - https://github.com/klever-io/klever-go/security/advisories/GHSA-26r5-4mm2-px5c - - https://github.com/klever-io/klever-go/security/advisories/GHSA-26r5-4mm2-px5c Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrIRl8JEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcme4f7RlQ4ZHGwYt+mU/UdOOpQGTcgVUtRx5gPCp sK1IchYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAACdOQD9G8haqBKGyx3nwMh0 UNqmSDJFafUHWsVtVOL5oWMBlfAA/37OdIhsDvGPMM1ePIOLK+ftsm3NPMsh fGHeFmAk70oA =FE+W -----END PGP SIGNATURE-----