CVE-2026-71479

🟠 Łataj w tym tygodniu

Przepełnienie w New API pozwala niskoprawnemu użytkownikowi na nieautoryzowane zyski finansowe.

CVSS
9.1
EPSS
0.5%
Exploit
none
Vendor
Opis źródłowy (NVD)

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities can overflow conversions in common/quota_math.go and related settlement paths, allowing a low-privileged account with positive balance or an active subscription to turn a negative charge into account credit and potentially drain upstream funds. This issue is fixed in version 1.0.0-rc.18.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.5%
Opublikowano (NVD)2026-08-17 16:17:44 UTC
Ostatnia modyfikacja (NVD)2026-09-18 20:09:01 UTC
Referencje