QuantumNous has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 5. The median CVSS is 7.7 (high), with 2 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.7
- Publish → KEV
- —
- Last 90 days
- 7 prev 0
Products
- github.com/QuantumNous/new-api 7
Worst active — by depth score
CVE-2026-71479Critical· 9.1New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system50CVE-2026-64859Critical· 9.1New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system50CVE-2026-33655High· 7.7New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs42CVE-2026-64868High· 7.5New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system41CVE-2026-44342Medium· 5.3New API is vulnerable to CSRF through user email binding29
QuantumNous vulnerabilities
CVEs affecting QuantumNous, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-64859Critical· 9.1New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token bec…
CVE-2026-64868High· 7.5New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodie…
CVE-2026-64866MediumNew API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELE…
CVE-2026-71479Critical· 9.1New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio…
CVE-2026-64865MediumNew API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because co…
CVE-2026-33655High· 7.7New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
CVE-2026-44342Medium· 5.3New API is vulnerable to CSRF through user email binding
New API is vulnerable to CSRF through user email binding