New-Api
QuantumNous · 18 CVEs
QuantumNous new-api Revoked API Token token session expiration
Aug 31, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
Aug 17, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting)
Aug 17, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users
Aug 17, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging
Aug 17, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
Aug 17, 2026
New API CSRF in email and WeChat account binding endpoints
Jul 9, 2026
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
Jul 9, 2026
QuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authorization
May 23, 2026
QuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injection
May 23, 2026
New API: SSRF Filter Bypass via 0.0.0.0
May 8, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
May 8, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure
Mar 23, 2026
New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check
Mar 23, 2026
New API has Potential XSS in its MarkdownRenderer component
Feb 24, 2026
New API has an SQL LIKE Wildcard Injection DoS via Token Search
Feb 24, 2026
QuantumNous New API Has SSRF Bypass
Nov 24, 2025
New API has Authenticated Server-Side Request Forgery (SSRF) issue
Oct 9, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-82909 | QuantumNous new-api Revoked API Token token session expiration | MEDIUM | 0.39% | Aug 31, 2026 |
| CVE-2026-64865 | New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass | MEDIUM | 0.29% | Aug 17, 2026 |
| CVE-2026-71479 | New API: Integer overflow in quota billing yields negative charges (self-crediting) | CRITICAL | 0.65% | Aug 17, 2026 |
| CVE-2026-64866 | New API: Admin can reset passkeys for same-level or higher-privileged users | MEDIUM | 0.47% | Aug 17, 2026 |
| CVE-2026-64868 | New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging | HIGH | 0.64% | Aug 17, 2026 |
| CVE-2026-64859 | New API: User List API Leaks Root User Access Token Leading to Privilege Escalation | CRITICAL | 0.63% | Aug 17, 2026 |
| CVE-2026-44342 | New API CSRF in email and WeChat account binding endpoints | MEDIUM | 0.19% | Jul 9, 2026 |
| CVE-2026-33655 | New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs | HIGH | 0.44% | Jul 9, 2026 |
| CVE-2026-9306 | QuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authorization | MEDIUM | 0.46% | May 23, 2026 |
| CVE-2026-9305 | QuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injection | MEDIUM | 0.32% | May 23, 2026 |
| CVE-2026-42339 | New API: SSRF Filter Bypass via 0.0.0.0 | HIGH | 0.30% | May 8, 2026 |
| CVE-2026-41432 | New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud | HIGH | 0.75% | May 8, 2026 |
| CVE-2026-32879 | New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure | MEDIUM | 0.46% | Mar 23, 2026 |
| CVE-2026-30886 | New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check | MEDIUM | 0.36% | Mar 23, 2026 |
| CVE-2026-25802 | New API has Potential XSS in its MarkdownRenderer component | HIGH | 0.27% | Feb 24, 2026 |
| CVE-2026-25591 | New API has an SQL LIKE Wildcard Injection DoS via Token Search | HIGH | 0.64% | Feb 24, 2026 |
| CVE-2025-62155 | QuantumNous New API Has SSRF Bypass | HIGH | 0.28% | Nov 24, 2025 |
| CVE-2025-59146 | New API has Authenticated Server-Side Request Forgery (SSRF) issue | HIGH | 0.24% | Oct 9, 2025 |
Showing 1 to 18 of 18 CVEs