Vulnerability Report: GO-2026-6245
- CVE-2026-64868, GHSA-v828-m3pf-vq9q
- Affects: github.com/QuantumNous/new-api
- Published: Aug 18, 2026
- Unreviewed
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api
For detailed information about this vulnerability, visit https://github.com/QuantumNous/new-api/security/advisories/GHSA-v828-m3pf-vq9q.
Affected Modules
-
PathGo Versions
-
before v1.0.0-rc.11
Aliases
References
- https://github.com/QuantumNous/new-api/security/advisories/GHSA-v828-m3pf-vq9q
- https://github.com/QuantumNous/new-api/commit/d2f7f9ee3adf3ef66798783a60d7bc712451c85c
- https://github.com/QuantumNous/new-api/pull/5244
- https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.11
- https://vuln.go.dev/ID/GO-2026-6245.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.