github.com/quantumnous/new-api
A unified AI model hub for aggregation & distribution. It supports cross-converting various LLMs into OpenAI-compatible, Claude-compatible, or Gemini-compatible formats. A centralized gateway for personal and enterprise model management.
Activity
- Latest release
- 2d ago
- Total releases
- 80
- Cadence
- ~3 days
- Last 12 months
- 71
Reach
- Stars
- 48.0k
Details
- First release
- Dec 11, 2023
| Version | Released | |
|---|---|---|
v1.0.0-rc.37
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.37
pre
Dependencies (70)
+ 62 more |
|
v1.0.0-rc.36
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.36
pre
Dependencies (70)
+ 62 more |
|
v1.0.0-rc.35
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.35
pre
Dependencies (70)
+ 62 more |
|
v1.0.0-rc.34
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.34
pre
Dependencies (70)
+ 62 more |
|
v1.0.0-rc.33
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.33
pre
Dependencies (68)
+ 60 more |
|
v1.0.0-rc.32
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.32
pre
Dependencies (68)
+ 60 more |
|
v1.0.0-rc.31
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.31
pre
Dependencies (68)
+ 60 more |
|
v1.0.0-rc.30
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.30
pre
Dependencies (68)
+ 60 more |
|
v1.0.0-rc.29
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.29
pre
Dependencies (68)
+ 60 more |
|
v1.0.0-rc.28
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.28
pre
Dependencies (67)
+ 59 more |
|
v1.0.0-rc.27
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.27
pre
Dependencies (67)
+ 59 more |
|
v1.0.0-rc.26
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.26
pre
Dependencies (65)
+ 57 more |
|
v1.0.0-rc.25
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.25
pre
Dependencies (65)
+ 57 more |
|
v1.0.0-rc.24
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.24
pre
Dependencies (65)
+ 57 more |
|
v1.0.0-rc.23
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.23
pre
Dependencies (65)
+ 57 more |
|
v1.0.0-rc.22
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.22
pre
Dependencies (59)
+ 51 more |
|
v1.0.0-rc.21
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.21
pre
Dependencies (59)
+ 51 more |
|
v1.0.0-rc.20
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.20
pre
Dependencies (59)
+ 51 more |
|
v1.0.0-rc.19-i18nfix.2
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.19-i18nfix.2
pre
Dependencies (59)
+ 51 more |
|
v1.0.0-rc.19-i18nfix.1
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.19-i18nfix.1
pre
Dependencies (59)
+ 51 more |
|
v1.0.0-rc.19
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.19
pre
Dependencies (59)
+ 51 more |
|
v1.0.0-rc.18
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.18
pre
Dependencies (59)
+ 51 more |
|
v1.0.0-rc.17
pre
6 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.17
pre
Dependencies (59)
+ 51 more |
|
v1.0.0-rc.16
pre
6 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.16
pre
Dependencies (59)
+ 51 more |
|
v1.0.0-rc.15
pre
7 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.15
pre
Dependencies (58)
+ 50 more |
|
v1.0.0-rc.14
pre
7 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.14
pre
Dependencies (56)
+ 48 more |
|
v1.0.0-rc.13
pre
7 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.13
pre
Dependencies (56)
+ 48 more |
|
v1.0.0-rc.12
pre
7 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.12
pre
Dependencies (56)
+ 48 more |
|
v1.0.0-rc.11
pre
7 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.11
pre
Dependencies (56)
+ 48 more |
|
v1.0.0-rc.10
pre
8 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.10
pre
Dependencies (56)
+ 48 more |
|
v1.0.0-rc.9
pre
3 CVEs
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.9
pre
Dependencies (56)
+ 48 more |
|
v1.0.0-rc.8
pre
3 CVEs
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.8
pre
Dependencies (56)
+ 48 more |
|
v1.0.0-rc.7
pre
3 CVEs
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.7
pre
Dependencies (55)
+ 47 more |
|
v1.0.0-rc.6
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.6
pre
Dependencies (55)
+ 47 more |
|
v1.0.0-rc.4
pre
5 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v1.0.0-rc.4
pre
Dependencies (55)
+ 47 more |
|
v0.13.0
minor
8 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.13.0
minor
Dependencies (55)
+ 47 more |
|
v0.12.15
patch
8 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.12.15
patch
Dependencies (54)
+ 46 more |
|
v0.12.13
patch
8 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.12.13
patch
Dependencies (54)
+ 46 more |
|
v0.12.12
patch
8 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.12.12
patch
Dependencies (54)
+ 46 more |
|
v0.12.9
patch
9 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-41432
GO-2026-5753
GHSA-xff3-5c9p-2mr4
Jun 25, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api Fixed in
0.12.10
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.12.9
patch
Dependencies (54)
+ 46 more |
|
v0.12.4
patch
9 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-41432
GO-2026-5753
GHSA-xff3-5c9p-2mr4
Jun 25, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api Fixed in
0.12.10
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.12.4
patch
Dependencies (54)
+ 46 more |
|
v0.12.1
minor
9 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-41432
GO-2026-5753
GHSA-xff3-5c9p-2mr4
Jun 25, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api Fixed in
0.12.10
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.12.1
minor
Dependencies (54)
+ 46 more |
|
v0.11.9-alpha.1
pre
11 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33655
GO-2026-5930
GHSA-6qcr-qxgr-m7fv
Jul 17, 2026
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-44342
GO-2026-5929
GHSA-26v7-h57m-gh9m
Jul 17, 2026
New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-41432
GO-2026-5753
GHSA-xff3-5c9p-2mr4
Jun 25, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api Fixed in
0.12.10
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.11.9-alpha.1
pre
Dependencies (54)
+ 46 more |
|
v0.11.8
patch
11 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33655
GO-2026-5930
GHSA-6qcr-qxgr-m7fv
Jul 17, 2026
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-44342
GO-2026-5929
GHSA-26v7-h57m-gh9m
Jul 17, 2026
New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-41432
GO-2026-5753
GHSA-xff3-5c9p-2mr4
Jun 25, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api Fixed in
0.12.10
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.11.8
patch
Dependencies (54)
+ 46 more |
|
v0.11.7
minor
11 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33655
GO-2026-5930
GHSA-6qcr-qxgr-m7fv
Jul 17, 2026
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-44342
GO-2026-5929
GHSA-26v7-h57m-gh9m
Jul 17, 2026
New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-41432
GO-2026-5753
GHSA-xff3-5c9p-2mr4
Jun 25, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api Fixed in
0.12.10
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.11.7
minor
Dependencies (54)
+ 46 more |
|
v0.11.4-alpha.3
pre
11 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33655
GO-2026-5930
GHSA-6qcr-qxgr-m7fv
Jul 17, 2026
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-44342
GO-2026-5929
GHSA-26v7-h57m-gh9m
Jul 17, 2026
New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-41432
GO-2026-5753
GHSA-xff3-5c9p-2mr4
Jun 25, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api Fixed in
0.12.10
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.11.4-alpha.3
pre
Dependencies (53)
+ 45 more |
|
v0.11.4-alpha.2
pre
11 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33655
GO-2026-5930
GHSA-6qcr-qxgr-m7fv
Jul 17, 2026
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-44342
GO-2026-5929
GHSA-26v7-h57m-gh9m
Jul 17, 2026
New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-41432
GO-2026-5753
GHSA-xff3-5c9p-2mr4
Jun 25, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api Fixed in
0.12.10
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.11.4-alpha.2
pre
Dependencies (53)
+ 45 more |
|
v0.11.2-patch.1
pre
12 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33655
GO-2026-5930
GHSA-6qcr-qxgr-m7fv
Jul 17, 2026
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-44342
GO-2026-5929
GHSA-26v7-h57m-gh9m
Jul 17, 2026
New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-41432
GO-2026-5753
GHSA-xff3-5c9p-2mr4
Jun 25, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api Fixed in
0.12.10
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-30886
GO-2026-4814
GHSA-f35r-v9x5-r8mc
Mar 26, 2026
New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check in github.com/QuantumNous/new-api New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check in github.com/QuantumNous/new-api Fixed in
0.11.4-alpha.2
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.11.2-patch.1
pre
Dependencies (53)
+ 45 more |
|
v0.11.1-alpha.2
pre
12 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33655
GO-2026-5930
GHSA-6qcr-qxgr-m7fv
Jul 17, 2026
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-44342
GO-2026-5929
GHSA-26v7-h57m-gh9m
Jul 17, 2026
New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-41432
GO-2026-5753
GHSA-xff3-5c9p-2mr4
Jun 25, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api Fixed in
0.12.10
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-30886
GO-2026-4814
GHSA-f35r-v9x5-r8mc
Mar 26, 2026
New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check in github.com/QuantumNous/new-api New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check in github.com/QuantumNous/new-api Fixed in
0.11.4-alpha.2
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.11.1-alpha.2
pre
Dependencies (53)
+ 45 more |
|
v0.11.0-alpha.7
pre
12 CVEs
CVE-2026-64866
GO-2026-6244
GHSA-p845-629j-rcj6
Aug 18, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64859
GO-2026-6240
GHSA-6x2c-phff-wx57
Aug 18, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.7
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-71479
GO-2026-6242
GHSA-8r8v-xf7q-rcpr
Aug 18, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.18
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64865
GO-2026-6243
GHSA-j6gc-4893-qwmp
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.16
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-64868
GO-2026-6245
GHSA-v828-m3pf-vq9q
Aug 18, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api Fixed in
1.0.0-rc.11
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-33655
GO-2026-5930
GHSA-6qcr-qxgr-m7fv
Jul 17, 2026
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-44342
GO-2026-5929
GHSA-26v7-h57m-gh9m
Jul 17, 2026
New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api New API is vulnerable to CSRF through user email binding in github.com/QuantumNous/new-api Fixed in
0.12.0-alpha.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-41432
GO-2026-5753
GHSA-xff3-5c9p-2mr4
Jun 25, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud in github.com/QuantumNous/new-api Fixed in
0.12.10
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42339
GO-2026-5652
GHSA-v5c3-6wvc-pc2q
Jun 25, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-30886
GO-2026-4814
GHSA-f35r-v9x5-r8mc
Mar 26, 2026
New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check in github.com/QuantumNous/new-api New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check in github.com/QuantumNous/new-api Fixed in
0.11.4-alpha.2
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-32879
GO-2026-4813
GHSA-5353-f8fq-65vc
Mar 26, 2026
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api Updated Mar 26, 2026 · Source: OSV.dev
CVE-2025-62155
GO-2025-4154
GHSA-9f46-w24h-69w4
Dec 15, 2025
new-api is vulnerable to SSRF Bypass in one-api new-api is vulnerable to SSRF Bypass in one-api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/QuantumNous/new-api before v0.9.6. References Updated Dec 15, 2025 · Source: OSV.dev |
v0.11.0-alpha.7
pre
Dependencies (53)
+ 45 more |