CVE-2026-64865

⚪ Do wiadomości

Wyścig warunków w New API pozwala na sztuczne zwiększenie limitu użytkownika.

CVSS
0.0
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because controller/user.go calls User.Update and updateUserCache performs a full RedisHSetObj write to user:.Quota, overwriting concurrent HINCRBY deductions and allowing an authenticated user to keep cached quota artificially high. This issue is fixed in version 1.0.0-rc.16.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS0.0
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-08-17 16:17:22 UTC
Ostatnia modyfikacja (NVD)2026-09-18 20:09:01 UTC
Referencje