Newapi
Newapi NEW API: vulnerabilidades y CVE
Newapi NEW API tiene 16 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses15
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-71479 | Crítica (9.1) | 0.65% | — | 17 ago 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens,… |
| CVE-2026-64868 | Alta (7.5) | 0.64% | — | 17 ago 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log… |
| CVE-2026-64866 | Media (5.1) | 0.47% | — | 17 ago 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole… |
| CVE-2026-64865 | Media (6) | 0.29% | — | 17 ago 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay… |
| CVE-2026-64859 | Crítica (9.1) | 0.63% | — | 17 ago 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken… |
| CVE-2026-44342 | Media (5.3) | 0.19% | — | 9 jul 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET… |
| CVE-2026-33655 | Alta (7.7) | 0.44% | — | 9 jul 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with… |
| CVE-2026-42339 | Alta (7.1) | 0.30% | — | 8 may 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in… |
| CVE-2026-41432 | Alta (8.2) | 0.75% | — | 8 may 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated… |
| CVE-2026-32879 | Media (4.9) | 0.46% | — | 23 mar 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user… |
| CVE-2026-30886 | Media (6.5) | 0.36% | — | 23 mar 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure Direct Object Reference (IDOR) vulnerability in the video proxy… |
| CVE-2026-25802 | Media (5.4) | 0.27% | — | 24 feb 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing… |
| CVE-2026-25591 | Alta (7.1) | 0.64% | — | 24 feb 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint… |
| CVE-2025-62155 | Alta (8.5) | 0.28% | — | 25 nov 2025 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.9.6, a recently patched SSRF vulnerability contains a bypass method that can bypass the… |
| CVE-2025-59146 | Alta (8.5) | 0.24% | — | 9 oct 2025 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in versions prior to 0.9.0.5. A feature… |
| CVE-2025-55573 | Alta (8.8) | 0.42% | — | 22 ago 2025 | QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS). |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.