CVE 7.1 HIGH

New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud_CVE-2026-41432

7.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Description

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated attacker to forge webhook events and credit arbitrary quota to their account without making any payment. This issue has been patched in version 0.12.10.

Basic Information

ID CVE-2026-41432
Source GitHub_M
Published May 8, 2026 at 22:21

Affected Product

Vendor QuantumNous
Product new-api
Version < 0.12.10
Affected Versions QuantumNous new-api < 0.12.10

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.