Affected by GO-2025-4154
and 7 other vulnerabilities
GO-2025-4154: new-api is vulnerable to SSRF Bypass in one-api
GO-2026-4813: New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api
GO-2026-5652: QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 in github.com/QuantumNous/new-api
GO-2026-6240: New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api
GO-2026-6242: New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api
GO-2026-6243: New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api
GO-2026-6244: New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api
GO-2026-6245: New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api