CVE-2026-64868highCWE-400CWE-770

CVE-2026-64868: falha de alta gravidade em QuantumNous new-api

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging

Publicada em

21Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 7.5epss 0.6%
probabilidade de exploração
0.6%top 51% das CVEs
exploração observada
nãonenhuma fonte reporta
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodies before signature validation in router/api-router.go and the payment controllers, allowing an unauthenticated attacker to cause memory pressure, container restarts, or disk exhaustion without forging a successful payment. This issue is fixed in version 1.0.0-rc.11.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Produtos afetados
QuantumNous · new-api