CVE-2026-25591Disclosure(newapi / new_api)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch newapi new_api systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated users to cause denial of service through resource exhaustion by crafting malicious search patterns. The token search endpoint accepts user-supplied `keyword` and `token` parameters that are directly concatenated into SQL LIKE clauses without escaping wildcard characters (`%`, `_`). This allows attackers to inject patterns that trigger expensive database queries. Version 0.10.8-alpha.10 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-943

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • new_api

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-24); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
new_api

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-24: 4Mentions · 2026-03-02: 1Mentions · 2026-03-12: 1Patch / Workaround · 2026-02-24: 2Technical Details · 2026-02-24: 402-2403-0203-12
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-244
Disclosure3Patch1
2026-03-021
General1
2026-03-121
General1
Full discourse6 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25591 SQL Injection in New API Token Search Endpoint Causing Denial of Service https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25591

    Post summary

    A new SQL injection vulnerability (CVE-2026-25591) in an API token search endpoint can cause a denial of service.

    0001045
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25591 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injecti… https://www.cve.org/CVERecord?id=CVE-2026-25591

    Post summary

    CVE-2026-25591 is a SQL LIKE wildcard injection in the New API LLM gateway, fixed in version 0.10.8-alpha.10, with no PoC, exploit, or active exploitation details provided.

    00010227
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25591: The Percent Sign of Death: Crashing QuantumNous New API with Wildcard Injection A high-severity Denial of Service (DoS) vulnerability exists in the QuantumNous 'New API' system, an AI model gateway. By exploiting a lack of input saniti... https://cvereports.com/reports/CVE-2026-25591

    Post summary

    A high‑severity DoS vulnerability in QuantumNous’ New API due to unsanitized wildcard input is disclosed, but no PoC, exploit, or patch details are provided.

    0001052
    31 followersView on X
  • Prateek Tomar@Prateektomar
    General

    Security deep dive: Critical Analysis CVE-2026-25591 - New API is a large language mode LLM.... Actionable advice for practitioners. Read more: https://threatops.tech/blog/critical-analysis-cve-2026-25591-new-api-is-a-large-language-mode-llm-gateway-and-artificia-march-12 #Cybe

    Post summary

    A blog post titled "Critical Analysis CVE-2026-25591" is referenced, promising actionable advice, but the excerpt lacks any concrete technical details, exploit code, or patch information.

    0000056
    93 followersView on X
  • AIGuardr@AIGuardr
    General

    Data authorities warn about AI generating realistic, non-consensual images of individuals. Risks include privacy violations and harm to children. 🚨 🌐 🛡️ https://www.sentinelone.com/vulnerability-database/cve-2026-25591/

    Post summary

    The post references a CVE via a link but offers no details on the vulnerability, exploitation, or mitigation.

    00000122
    3.9K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH-severity alert: QuantumNous new-api <0.10.8-alpha.10 has a SQL wildcard injection in /api/token/search. Authenticated users can trigger DoS via crafted queries. Patch now! 🔒 https://radar.offseq.com/threat/cve-2026-25591-cwe-943-improper-neutralization-of--2ce4358a #Off... https://t.co/8IL7dxNnwV

    Post summary

    QuantumNous new-api <0.10.8-alpha.10 is vulnerable to a SQL wildcard injection that can cause DoS for authenticated users; a patch is now available.

    0000063
    269 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appnewapinew_api---
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--
Appnewapinew_api0.10.8--

Explore more