CVE-2026-71479

Summary

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities can overflow conversions in common/quota_math.go and related settlement paths, allowing a low-privileged account with positive balance or an active subscription to turn a negative charge into account credit and potentially drain upstream funds. This issue is fixed in version 1.0.0-rc.18.

Affected Software

VendorProductVersion RangeStatus
QuantumNousnew-api< 1.0.0-rc.18affected

Weaknesses

  • CWE-190: CWE-190: Integer Overflow or Wraparound
  • CWE-682: CWE-682: Incorrect Calculation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References