THREAT OPS › Threat News › [GHSA] GHSA-v358-wf77-39xv (high) — klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
[GHSA] GHSA-v358-wf77-39xv (high) — klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
GHSA-v358-wf77-39xv Severity: high CVE: CVE-2026-55763
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
## Summary In `processPercentageRoyaltiesTransfer` the royalty pool is collected from the sender by `SubFromBalance` that is ordered **after** the split loop and after `if royaltiesToPay <= 0 { return Ok }`. The split-payout guard rejects only an allocation
Indicators of compromise
- ec2a8e8d17136986756141f598f869803528ab12840416671b09622eaf12bc7fsha256
- 37527757b10dcf968b86cc3c0abf971c70e81aef0348b4a5b7d4ccc1bf3706b1sha256
- CVE-2026-55763cve
Original source: https://github.com/advisories/GHSA-v358-wf77-39xv