A vulnerability was discovered in Klever-Go's KVM implementation, exposing a read-only execution mechanism that could be exploited to delete contracts. The issue was caused by the indirect contract delete and upgrade paths not rejecting execution when in read-only mode. The fix was introduced in version 1.7.17. This vulnerability impacts users of Klever-Go, particularly those relying on read-only calls to [truncated]
A remote, unauthenticated denial-of-service vulnerability exists in Klever-Go prior to version 1.7.17. The flaw resides in the `Batch.Decompress` function within `data/batch/batch.go`, where an attacker can trigger multi-gigabyte heap allocations on a receiving node by sending a crafted gossip payload of less than 50 KiB. A single malicious packet is sufficient to cause an out-of-memory (OOM) termination [truncated]