What is CVE-2026-49343?
CVE-2026-49343 is a resource-exhaustion vulnerability in the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers leak bounded throttler slots on error paths within the syncDataTrie() function, potentially leading to denial of service. Users should upgrade to version 1.7.18 or later to mitigate the issue.
Azərbaycanca: CVE-2026-49343, Klever-Go blockchain protokolunun Go dilində tətbiqində aşkar edilmiş resurs tükənməsi zəifliyidir. 1.7.18-dən əvvəlki versiyalarda, account-data trie sinxronizatorlarında səhv yollarında bounded throttler slot-larının sızması baş verir. Bu, syncDataTrie() funksiyasında resursların tükənməsinə səbəb ola bilər, istifadəçilərə versiyanı ən azı 1.7.18-ə yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
Which function in the Klever-Go protocol can lead to resource exhaustion due to CVE-2026-49343?
The CVE-2026-49343 vulnerability can lead to resource exhaustion in the syncDataTrie() function due to bounded throttler slot leaks on error paths.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.