CVE-2026-86065: Denial of Service via Resource Exhaustion in klever-go WebSocket Subscription Endpoint
Vulnerability ID: CVE-2026-86065
CVSS Score: 7.5
Published: 2026-09-23
Prior to version 1.7.20, the default-open WebSocket /subscribe endpoint in klever-go was vulnerable to remote resource exhaustion. Unauthenticated, remote attackers could crash validator and node processes by exploiting unbounded frame reads, uncapped concurrent connections, unrestricted memory allocation for subscription address keys, and a permanent memory leak in subscription map tracking on client disconnects.
TL;DR
Unauthenticated remote attackers can crash klever-go nodes via WebSocket resource exhaustion on the /subscribe endpoint, mitigated in v1.7.20.
Technical Details
- CWE ID: CWE-770
- Attack Vector: Network (Unauthenticated)
- CVSS v3.1: 7.5 (High)
- Exploit Status: None (Theoretical, except regression tests)
- KEV Status: Not listed
- Remediation: Upgrade to v1.7.20
Affected Systems
- klever-go validator nodes
- klever-go observer nodes
-
klever-go: < 1.7.20 (Fixed in:
1.7.20)
Code Analysis
Commit: b8af922
Fix websocket resource leak, restrict message sizing, and implement global/per-IP connection limits.
Mitigation Strategies
- Upgrade to klever-go version 1.7.20 or later.
- Deploy reverse proxy with connection and rate limits.
- Restrict public access to the /subscribe endpoint using firewall rules.
Remediation Steps:
- Identify running klever-go daemon version.
- Download and compile the v1.7.20 release or newer.
- Restart the node with the updated binary.
- Verify websocket connection limits are active in configuration.
References
Read the full report for CVE-2026-86065 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)