-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0176 ============================================================ Advisory-ID: 0xCERT-2026-0176 Severity: High Published: 2026-09-23T20:17:16.893Z Updated: 2026-10-08T22:46:37.243Z Chains: n/a URL: https://www.0xcert.com/advisory/0xCERT-2026-0176 Title: CVE-2026-82409: Klever-Go Summary - ------- Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and NDJSON request without escaping it. The SetAccountName transaction accepts valid UTF-8 account names containing quotes, backslashes, and newlines, and the resulting name is stored in consensus account state. When an indexer processes the account, those characters can break the JSON string, reject a bulk batch, or inject additional bulk actions that create, overwrite, or delete… Details - ------- Summary Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and NDJSON request without escaping it. The SetAccountName transaction accepts valid UTF-8 account names containing quotes, backslashes, and newlines, and the resulting name is stored in consensus account state. When an indexer processes the account, those characters can break the JSON string, reject a bulk batch, or inject additional bulk actions that create, overwrite, or delete documents in indices writable by the indexer. The persistent state value is replayed by new or historical indexers, and direct access to the indexing host or Elasticsearch port is not required. This issue is fixed in version 1.7.20. Severity High (CVSS 8.4), as scored by NVD. Weakness - - CWE-116 Recommended actions - - Check whether you run or depend on the affected component and version - - Apply the vendor's fix or mitigation from the references below Source & attribution This 0xCERT advisory summarises CVE-2026-82409 from the U.S. National Vulnerability Database: https://nvd.nist.gov/vuln/detail/CVE-2026-82409. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://nvd.nist.gov/vuln/detail/CVE-2026-82409 - - https://github.com/klever-io/klever-go/commit/f00366768b24be18fa7ae9de2e1905caa8b350af - - https://github.com/klever-io/klever-go/commit/f54ea730cc80a3ba4f906586a7d221b281548190 - - https://github.com/klever-io/klever-go/releases/tag/v1.7.20 - - https://github.com/klever-io/klever-go/security/advisories/GHSA-7c7c-373r-gfjj - - https://github.com/klever-io/klever-go/security/advisories/GHSA-7c7c-373r-gfjj Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrIRlsJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmfHZvUvRy5OaqG3AXcgIBgF3cLyQWMai91vBUe4 ouzZxhYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAACzHQEA8rWbLBFr5ws3eG7+ Mef+hp2ZCmjCcaTNsF69ICZq7goBAMcW/IS9Er9xtOM+5oNqtIB98dtl+KEo gQlkh4RM2a8M =WmyX -----END PGP SIGNATURE-----