High severity7.5NVD Advisory· Published Aug 17, 2026· Updated Sep 18, 2026
CVE-2026-64868
CVE-2026-64868
Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodies before signature validation in router/api-router.go and the payment controllers, allowing an unauthenticated attacker to cause memory pressure, container restarts, or disk exhaustion without forging a successful payment. This issue is fixed in version 1.0.0-rc.11.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/QuantumNous/new-apiGo | < 1.0.0-rc.11 | 1.0.0-rc.11 |
Affected products
3- Range: >=1.0.0-rc.11
- ghsa-coords2 versionspkg:golang/github.com/quantumnous/new-apipkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 1.0.0-rc.11+ 1 more
- (no CPE)range: < 1.0.0-rc.11
- (no CPE)range: < 0.0.20260827T195228-160000.1.1
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-v828-m3pf-vq9qghsaADVISORY
- github.com/QuantumNous/new-api/commit/d2f7f9ee3adf3ef66798783a60d7bc712451c85cnvdWEB
- github.com/QuantumNous/new-api/pull/5244nvdWEB
- github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.11nvdWEB
- github.com/QuantumNous/new-api/security/advisories/GHSA-v828-m3pf-vq9qnvdWEB
News mentions
0No linked articles in our index yet.