Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8r8v-xf7q-rcpr | New API: Integer overflow in quota billing yields negative charges (self-crediting) |
Mon, 17 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quantumnous
Quantumnous new-api |
|
| Vendors & Products |
Quantumnous
Quantumnous new-api |
Mon, 17 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities can overflow conversions in common/quota_math.go and related settlement paths, allowing a low-privileged account with positive balance or an active subscription to turn a negative charge into account credit and potentially drain upstream funds. This issue is fixed in version 1.0.0-rc.18. | |
| Title | New API: Integer overflow in quota billing yields negative charges (self-crediting) | |
| Weaknesses | CWE-190 CWE-682 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T18:59:30.302Z
Reserved: 2026-08-06T19:56:23.724Z
Link: CVE-2026-71479
Updated: 2026-08-17T18:59:25.755Z
Status : Received
Published: 2026-08-17T16:17:44.307
Modified: 2026-08-17T19:16:35.383
Link: CVE-2026-71479
No data.
OpenCVE Enrichment
Updated: 2026-08-17T17:30:18Z
Github GHSA