Overflow Vulnerability in QuantumNous New API AI Management System
CVE-2026-71479

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-71479?

An overflow vulnerability exists in the QuantumNous New API, allowing low-privileged users with an active subscription to manipulate various parameters including image counts and audio durations, thereby converting valid charges into account credits. This exploit could enable users to drain funds from upstream resources without proper authorization. The issue has been addressed in version 1.0.0-rc.18.

Affected Version(s)

new-api < 1.0.0-rc.18

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.