SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-71479

CRITICAL · CVSS 9.1 EPSS 0.52% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

The vulnerability allows low-privileged users with a positive balance or active subscription to exploit overflow conversions in the quota management system, potentially converting negative charges into account credit and draining upstream funds. Organizations utilizing the affected large language model gateway and AI asset management system should prioritize applying the patch in version 1.0.0-rc.18 to mitigate the risk of financial loss. Immediate action is crucial for any entity relying on this software for managing user accounts and billing.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-71479
Severity
CRITICAL
CVSS
9.1
EPSS
0.52%

Original NVD Description

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities can overflow conversions in common/quota_math.go and related settlement paths, allowing a low-privileged account with positive balance or an active subscription to turn a negative charge into account credit and potentially drain upstream funds. This issue is fixed in version 1.0.0-rc.18.