What is CVE-2026-47249?
CVE-2026-47249 affects the Klever-Go implementation of the Klever blockchain protocol. Prior to version 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification, allowing a connected peer to send a compressed direct request of only 442 bytes that expands to overwhelm network resources. Upgrading to version 1.7.18 is recommended to mitigate this issue.
Azərbaycanca: CVE-2026-47249, Klever-Go blockchain protokolunun Go dilindəki icrasında aşkar edilmişdir. 1.7.18-dən əvvəlki versiyalarda P2P resolver-in sorğu emalı məntiqində hash-array amplification zəifliyi mövcuddur ki, bu da uzaqdan bir peer-in cəmi 442 baytlıq sıxılmış sorğu ilə şəbəkə resurslarını həddindən artıq yükləməsinə imkan yaradır. Təsirə məruz qalan sistemlərdə 1.7.18 versiyasına yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
In which component of Klever-Go was CVE-2026-47249 discovered?
The vulnerability was discovered in the P2P resolver request handling logic.
What version should be upgraded to in order to mitigate CVE-2026-47249?
Upgrading to version 1.7.18 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.