SSRF Vulnerability in New API Gateway by QuantumNous
CVE-2025-62155
8.5HIGH
What is CVE-2025-62155?
A vulnerability in the New API gateway from QuantumNous allows an attacker to exploit a Server-Side Request Forgery (SSRF) issue. This flaw exists due to the improper handling of URL requests in versions prior to 0.9.6. The security patch was insufficient as it only enforces restrictions on the first URL request, allowing attackers to leverage 302 redirects to bypass security measures, gaining unauthorized access to internal network resources. The vulnerability has been resolved in version 0.9.6.
Affected Version(s)
new-api < 0.9.6
