Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v828-m3pf-vq9q | New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging |
Mon, 17 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quantumnous
Quantumnous new-api |
|
| Vendors & Products |
Quantumnous
Quantumnous new-api |
Mon, 17 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodies before signature validation in router/api-router.go and the payment controllers, allowing an unauthenticated attacker to cause memory pressure, container restarts, or disk exhaustion without forging a successful payment. This issue is fixed in version 1.0.0-rc.11. | |
| Title | New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging | |
| Weaknesses | CWE-400 CWE-770 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T16:31:08.189Z
Reserved: 2026-07-20T18:31:39.292Z
Link: CVE-2026-64868
Updated: 2026-08-17T16:30:51.038Z
Status : Received
Published: 2026-08-17T16:17:22.713
Modified: 2026-08-17T17:16:40.073
Link: CVE-2026-64868
No data.
OpenCVE Enrichment
Updated: 2026-08-17T17:30:18Z
Github GHSA