AI Asset Management System Vulnerability in New API by QuantumNous
CVE-2026-64865

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-64865?

A race condition vulnerability exists in the New API's user management component that allows authenticated users to exploit the system when making repeated updates. By sending multiple PUT requests to the /api/user/self endpoint before version 1.0.0-rc.16, users could interfere with the quota deduction process, resulting in inflated cached quotas. This flaw arises due to concurrent write operations in the user management logic, thereby compromising the integrity of user quota management. The issue has been addressed in version 1.0.0-rc.16.

Affected Version(s)

new-api < 1.0.0-rc.16

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.