{"id":"CVE-2026-64868","title":"New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system","summary":"New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodie…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400","CWE-770"],"vendor":"QuantumNous","product":"github.com/QuantumNous/new-api","affected":["github.com/QuantumNous/new-api < 1.0.0-rc.11"],"patched":["github.com/QuantumNous/new-api 1.0.0-rc.11"],"published":"2026-08-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:09:01.757","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-64868","references":[{"url":"https://github.com/QuantumNous/new-api/commit/d2f7f9ee3adf3ef66798783a60d7bc712451c85c","label":"security-advisories@github.com"},{"url":"https://github.com/QuantumNous/new-api/pull/5244","label":"security-advisories@github.com"},{"url":"https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.11","label":"security-advisories@github.com"},{"url":"https://github.com/QuantumNous/new-api/security/advisories/GHSA-v828-m3pf-vq9q","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-v828-m3pf-vq9q"}],"tags":["nvd","ghsa","go"],"epss":0.00467,"epssPercentile":0.39501,"aliases":["GHSA-v828-m3pf-vq9q"],"ecosystem":"go","ingestedAt":"2026-08-17T16:57:25.527Z","slug":"CVE-2026-64868","body":"## Overview\n\nNew API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodies before signature validation in router/api-router.go and the payment controllers, allowing an unauthenticated attacker to cause memory pressure, container restarts, or disk exhaustion without forging a successful payment. This issue is fixed in version 1.0.0-rc.11.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-64868)\n\nAffected packages:\n\n- `github.com/QuantumNous/new-api < 1.0.0-rc.11`\n\nPatched in:\n\n- `github.com/QuantumNous/new-api 1.0.0-rc.11`\n\nSource: https://github.com/advisories/GHSA-v828-m3pf-vq9q","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}