QuantumNous new-api, Integer Overflow in Quota Billing, CVE-2026-71479 (CRITICAL) -DC-Aug2026-1526

Listen to this Post

Vulnerability

New API is a large language model (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 1.0.0-rc.18, the platform contained a critical integer overflow vulnerability (CWE-190) in its quota billing calculation. Multiple billing paths accepted user-controlled quantity parameters—including image count n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities—and multiplied them into quota calculations without any upper-bound validation or overflow-safe integer conversion.
The attack leverages a crafted extreme value, such as image n = 18446744073686646784, which is a wrapped-negative value accepted by a `uint` field. The vulnerable code path performs conversions like int(float64(quota) n), causing the result to wrap past the int64/int32 range into a large negative quota. Critically, this overflow does not manifest at the pre-consume stage—the pre-consume gate correctly rejects `userQuota <= 0` and insufficient balance with HTTP 403. Instead, the negative quota takes effect at settlement, where it is equivalent to crediting the user's balance—turning a small positive balance into an enormous one. While the attacker must hold an account with a positive balance that at least covers the normal (un-inflated) pre-consume amount, the severity escalates dramatically when the deployment enables features that grant free starting balances: check-in rewards (CheckinSetting.Enabled), invite rebates (QuotaForInviter/QuotaForInvitee), or new-user quota gifts (QuotaForNewUser). With self-registration enabled by default, an attacker can mass-register to obtain seed balance for free, then inflate it via a single crafted request—effectively enabling unauthenticated exploitation.
The vulnerability was confirmed exploited in the wild. The response timeline (UTC+8): 2026-07-06 23:00—community user @lihui12388 reported exploitation; 2026-07-07 01:17—emergency fix released as v1.0.0-rc.18 (~2 hours after report); 2026-07-07—public disclosure; 2026-07-07 13:19—v1.0.0-rc.19 released with quota-saturation warning logs.

DailyCVE Form:

Platform: QuantumNous new-api
Version: < 1.0.0-rc.18
Vulnerability: Integer Overflow (CWE-190)
Severity: CRITICAL (CVSS 9.1)
Date: 2026-08-17

Prediction: Patch already released (2026-07-07)

What Undercode Say:

Check current version
new-api --version
Upgrade to patched version
For Docker deployments:
docker pull quantumNous/new-api:1.0.0-rc.18
docker stop new-api && docker rm new-api
docker run -d --name new-api quantumNous/new-api:1.0.0-rc.18
For source/build deployments:
git pull origin main
git checkout v1.0.0-rc.18
make build
systemctl restart new-api
Audit for past exploitation - check logs for abnormal negative consumption entries:
grep -i "negative" /var/log/new-api/consume.log
grep -i "quota_saturation" /var/log/new-api/admin.log
Check for abnormally inflated balances in database:
sqlite3 new-api.db "SELECT user_id, balance FROM users WHERE balance > 1000000 ORDER BY balance DESC;"

Exploit: (Educational Purposes!)

The exploit relies on the absence of upper-bound validation for user-controlled multipliers. A crafted request sends an extreme value (e.g., image n = 18446744073686646784) which is accepted by the `uint` field because it represents a wrapped-negative value. The vulnerable code then performs int(float64(quota) n), causing the multiplication to overflow and wrap past the int64/int32 range. Since the overflow only manifests at settlement (not at pre-consume), the pre-consume gate approves the request based on the un-inflated quota. At settlement, the negative quota is applied, which is equivalent to crediting the user’s balance rather than debiting it—turning a small positive balance into an enormous one. With free starting balance features enabled, an attacker can mass-register accounts and exploit each one with a single request.

Protection:

The fix was implemented via defense-in-depth:

  1. Upper-bound validation at request ingress—returns HTTP 400 on violation
  2. Local clamping of quantities on validation-bypass paths (passthrough/metadata/multipart)
  3. Centralized saturating conversions in common/quota_math.go—clamp to int32 and never wrap
    Saturation events are audited on consume/task logs under `admin_info.quota_saturation` (admin-only) and via request-correlated backend warnings. Operators should upgrade to v1.0.0-rc.18 or later immediately and audit logs for past exploitation indicators.

Impact:

A low-privilege user with a positive balance can massively inflate their own balance with a single crafted request (negative settlement = credit), violating billing integrity. Sustained abuse can drain the operator’s prepaid upstream funds and render billing/service unavailable. Exploitation in the wild has been confirmed. The CVSS 3.1 vector is `AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H` with a base score of 9.1 (CRITICAL).

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top