API Gateway Vulnerability in New API by QuantumNous
CVE-2026-64868

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-64868?

A flaw exists in the New API's handling of incoming webhook requests. Prior to version 1.0.0-rc.11, the system logs full request bodies before validating the signatures, which can be exploited by an unauthenticated attacker. This vulnerability allows attackers to create memory pressure, trigger container restarts, or exhaust disk resources without needing to forge any payment. Users are advised to update to version 1.0.0-rc.11 or later to mitigate the risk.

Affected Version(s)

new-api < 1.0.0-rc.11

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.