THREAT OPS › Threat News › [GHSA] GHSA-cgc5-v3f2-8m2v (critical) — Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
[GHSA] GHSA-cgc5-v3f2-8m2v (critical) — Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
GHSA-cgc5-v3f2-8m2v Severity: critical CVE: CVE-2026-54755
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
## Summary
The per-entry percentages of a KDA asset's **split royalties** are validated by summing them into a **`uint32`** accumulator and checking the *sum* against `HundredPercent (10000)`, with **no upper bound on each individual ent
Indicators of compromise
- 1e288135d138be61a1fc240775eed04fcb578cc7299b28bea9e47c79f86e60ebsha256
- 4e869e93f480c7735f08d6f807cd3c0bb1935131d9bacef75ca7e3402501d1e6sha256
- CVE-2026-54755cve
- http://127.0.0.1:8080/address/$R1url
Original source: https://github.com/advisories/GHSA-cgc5-v3f2-8m2v