Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-71479: New API can give users credit by abusing billing
CVE-2026-71479 · published 1 month ago
Summary
The New API gateway lets users specify values like image count or video length that are not checked correctly. By entering very large numbers, a user with a normal account can cause the system to calculate a negative charge, effectively giving the account a credit and risking loss of money. Upgrade to version 1.0.0‑rc.18 or later to fix the problem.
What to do
- Update github.com quantumnous to version 1.0.0-rc.18.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | quantumnous | new-api | < 1.0.0-rc.18 |
| go | github.com | quantumnous |
<= 1.0.0-rc.17 Fix: upgrade to 1.0.0-rc.18
|
Original advisory text
New API: Integer overflow in quota billing yields negative charges (self-crediting)
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities can overflow conversions in common/quota_math.go and related settlement paths, allowing a low-privileged account with positive balance or an active subscription to turn a negative charge into account credit and potentially drain upstream funds. This issue is fixed in version 1.0.0-rc.18.
References
- https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.18 URL
- https://github.com/QuantumNous/new-api/security/advisories/GHSA-8r8v-xf7q-rcpr Vendor Advisory
- https://github.com/advisories/GHSA-8r8v-xf7q-rcpr
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71479... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-71479 Vendor Advisory
- https://github.com/QuantumNous/new-api/commit/c9943d37ad93477dd937fc4901cc3c4e0f... Patch
- https://github.com/QuantumNous/new-api/commit/d0bd8aac742d1e160a5ca61743fe35f4ff... Patch
Severity
9.1
Critical
CVSS 3.1: 9.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-190Integer Overflow
CWE-682Incorrect Calculation
Timeline
Published17 Aug 2026
Updated25 Sep 2026
First seen17 Aug 2026
Track software like this
Free during beta