CVE-2026-41432

Source
https://cve.org/CVERecord?id=CVE-2026-41432
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-41432.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-41432
Aliases
Downstream
Related
Published
2026-05-08T22:21:32Z
Modified
2026-08-12T03:30:47Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L CVSS Calculator
Summary
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
Details

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated attacker to forge webhook events and credit arbitrary quota to their account without making any payment. This issue has been patched in version 0.12.10.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-1188",
        "CWE-345",
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41432.json"
}
References

Affected packages

Git / github.com/quantumnous/new-api

Affected ranges

Type
GIT
Repo
https://github.com/quantumnous/new-api
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:newapi:new_api:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.12.10"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.11.4-patch.1
v0.11.5
v0.11.6
v0.11.6-patch.1
v0.11.7
v0.11.8
v0.11.9
v0.11.9-alpha.1
v0.11.9-alpha.2
v0.11.9-alpha.3
v0.12.0
v0.12.0-alpha.1
v0.12.0-alpha.2
v0.12.1
v0.12.2
v0.12.3
v0.12.4
v0.12.5
v0.12.6
v0.12.7
v0.12.8
v0.12.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-41432.json"