DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-86065: CVE-2026-86065: Denial of Service via Resource Exhaustion in klever-go WebSocket Subscription Endpoint

CVE-2026-86065: Denial of Service via Resource Exhaustion in klever-go WebSocket Subscription Endpoint

Vulnerability ID: CVE-2026-86065
CVSS Score: 7.5
Published: 2026-09-23

Prior to version 1.7.20, the default-open WebSocket /subscribe endpoint in klever-go was vulnerable to remote resource exhaustion. Unauthenticated, remote attackers could crash validator and node processes by exploiting unbounded frame reads, uncapped concurrent connections, unrestricted memory allocation for subscription address keys, and a permanent memory leak in subscription map tracking on client disconnects.

TL;DR

Unauthenticated remote attackers can crash klever-go nodes via WebSocket resource exhaustion on the /subscribe endpoint, mitigated in v1.7.20.


Technical Details

  • CWE ID: CWE-770
  • Attack Vector: Network (Unauthenticated)
  • CVSS v3.1: 7.5 (High)
  • Exploit Status: None (Theoretical, except regression tests)
  • KEV Status: Not listed
  • Remediation: Upgrade to v1.7.20

Affected Systems

  • klever-go validator nodes
  • klever-go observer nodes
  • klever-go: < 1.7.20 (Fixed in: 1.7.20)

Code Analysis

Commit: b8af922

Fix websocket resource leak, restrict message sizing, and implement global/per-IP connection limits.

Mitigation Strategies

  • Upgrade to klever-go version 1.7.20 or later.
  • Deploy reverse proxy with connection and rate limits.
  • Restrict public access to the /subscribe endpoint using firewall rules.

Remediation Steps:

  1. Identify running klever-go daemon version.
  2. Download and compile the v1.7.20 release or newer.
  3. Restart the node with the updated binary.
  4. Verify websocket connection limits are active in configuration.

References


Read the full report for CVE-2026-86065 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)