CVE-2026-64868: Quantumnous New-API

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodies before signature validation in router/api-router.go and the payment controllers, allowing an unauthenticated attacker to cause memory pressure, container restarts, or disk exhaustion without forging a successful payment. This issue is fixed in version 1.0.0-rc.11.

Affected products

  • Quantumnous New-API: before 1.0.0-rc.11 (fixed in 1.0.0-rc.11)

Published 2026-08-17. Last modified 2026-09-18.