THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cgc5-v3f2-8m2v (critical) — Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)

[GHSA] GHSA-cgc5-v3f2-8m2v (critical) — Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)

highgithub_advisoriesPublished 2026-08-28

GHSA-cgc5-v3f2-8m2v Severity: critical CVE: CVE-2026-54755

Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)

## Summary

The per-entry percentages of a KDA asset's **split royalties** are validated by summing them into a **`uint32`** accumulator and checking the *sum* against `HundredPercent (10000)`, with **no upper bound on each individual ent

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cgc5-v3f2-8m2v