CVE-2026-71479

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities can overflow conversions in common/quota_math.go and related settlement paths, allowing a low-privileged account with positive balance or an active subscription to turn a negative charge into account credit and potentially drain upstream funds. This issue is fixed in version 1.0.0-rc.18.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-17 16:17

Updated : 2026-08-17 19:16


NVD link : CVE-2026-71479

Mitre link : CVE-2026-71479

CVE.ORG link : CVE-2026-71479


JSON object : View

Products Affected

No product.

CWE
CWE-190

Integer Overflow or Wraparound

CWE-682

Incorrect Calculation