{"id":"CVE-2026-49343","summary":"Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS","details":"Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a resource-exhaustion flaw that leaks bounded throttler slots on error paths. In syncDataTrie() (in both userAccountsSyncer.go and kappAccountsSyncer.go), StartProcessing() reserves a slot from the NumGoRoutinesThrottler, but the corresponding EndProcessing() is only called on the success path and on the duplicate-root early return. As a result, any error from trie.NewTrie(), trie.NewTrieSyncer(), or trieSyncer.StartSyncing() (including the network-dependent timeout path) permanently consumes one slot for the lifetime of the throttler. An attacker who can repeatedly cause trie-node sync failures or timeouts during bootstrap can exhaust the bounded throttler, after which further account-data trie syncs stop making progress and SyncAccounts() returns a timeout. Because epoch bootstrap in syncUserAccountsState() and syncKappAccountsState() aborts on any such error, this causes bootstrap to fail, a core availability issue affecting fresh, restarting, or resyncing nodes and validators. This issue is fixed in version 1.7.18.","aliases":["GHSA-fw38-pc54-jvx9","GO-2026-5379"],"modified":"2026-08-08T11:46:25.703698416Z","published":"2026-08-07T22:18:18.735Z","related":["openSUSE-SU-2026:21483-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-400","CWE-772"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49343.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49343.json"},{"type":"WEB","url":"https://github.com/klever-io/klever-go/releases/tag/v1.7.18"},{"type":"ADVISORY","url":"https://github.com/klever-io/klever-go/security/advisories/GHSA-fw38-pc54-jvx9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49343"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/klever-io/klever-go","events":[{"introduced":"0"},{"fixed":"785b77ccb27162506c888cb62657cd7117d23126"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.7.18"}],"source":"AFFECTED_FIELD"}}],"versions":["v1.7.17","v1.7.16","v1.7.15","v1.7.14"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49343.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}