QuantumNous New API是QuantumNous个人开发者的一个LLM网关和AI资产管理系统。 QuantumNous New API 1.0.0-rc.16之前版本存在竞争条件问题漏洞,该漏洞源于竞争条件问题,可能导致已认证用户通过重复的PUT /api/user/self请求更新语言或sidebar_modules时覆盖并发配额扣除,使缓存配额保持虚高。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| QuantumNous | new-api | < 1.0.0-rc.16 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| QuantumNous | new-api | < 1.0.0-rc.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64859 | 9.1 CRITICAL | New API: User List API Leaks Root User Access Token Leading to Privilege Escalation |
| CVE-2026-71479 | 9.1 CRITICAL | New API: Integer overflow in quota billing yields negative charges (self-crediting) |
| CVE-2026-64868 | 7.5 HIGH | New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body rea |
| CVE-2026-64866 | 5.1 MEDIUM | New API: Admin can reset passkeys for same-level or higher-privileged users |
No comments yet