CVE-2026-71479Active Exploitation

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities can overflow conversions in common/quota_math.go and related settlement paths, allowing a low-privileged account with positive balance or an active subscription to turn a negative charge into account credit and potentially drain upstream funds. This issue is fixed in version 1.0.0-rc.18.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190CWE-682

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-08-18)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-08-17: 2Mentions · 2026-08-18: 3Active Exploitation · 2026-08-18: 3Patch / Workaround · 2026-08-18: 2Technical Details · 2026-08-17: 1Technical Details · 2026-08-18: 308-1708-18
Signal classification3 categories
Active Exploitation
360.0%
Disclosure
120.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-172
Disclosure1General1
2026-08-183
Active Exploitation3
Full discourse5 posts
  • Netlas.io@Netlas_io
    Active Exploitation

    CVE-2026-71479: Integer overflow in New API, 9.1 rating 🔥 A recently disclosed integer overflow vulnerability in New API allows low-privileged accounts with a positive balance or an active subscription to credit themselves an arbitrarily large amount. This vulnerability is already being actively exploited in the wild! 👉https://nt.ls/XoA0U

    Post summary

    Integer overflow in New API lets low‑privileged accounts self‑credit unlimited amounts; this flaw is already being actively exploited in the wild.

    02013519
    7.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    CVE-2026-71479, a CVSS 9.1 integer overflow in New API billing, is exploited in the wild to self-credit balances. Update to rc.18 now. #CVE202671479 #IntegerOverflow #NewAPI #ExploitedInTheWild #AIGateway #BillingFraud https://securityonline.info/cve-2026-71479-new-api-integer-overflow/

    Post summary

    CVE-2026-71479, an integer overflow in New API billing, is actively exploited for self-credits, and a patch update rc.18 is now available.

    00021493
    12.8K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-71479 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds … https://www.cve.org/CVERecord?id=CVE-2026-71479

    Post summary

    The snippet only identifies the CVE and links to its record, with no additional details on the vulnerability, exploitation, or mitigation.

    000101.6K
    58.0K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Active Exploitation

    CyberSec Daily ✓ · 🤖 AI Infrastructure · August 18, 2026 🎯 Critical vulnerability in New API AI gateway confirmed exploited in the wild A critical vulnerability tracked as CVE-2026-71479 affects New API, an open-source gateway and management platform used with LLM and AI services. The issue carries a CVSS score of 9.1, and August 18 reporting indicates that exploitation has already been observed in the wild. The vulnerability affects billing-related logic and can allow unauthorized manipulation of account balances on vulnerable installations. The problem has been addressed in New API 1.0.0-rc.18, making upgrades a priority for exposed deployments. 🔗 Source: SecurityOnline / CVE vulnerability data #AISecurity #LLMSecurity #CVE202671479 #CyberSecurity #Vulnerability #AIInfrastructure #PatchNow

    Post summary

    CVE-2026-71479 is an actively exploited critical vulnerability in New API, with a public patch available.

    0000041
    75 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-71479 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds … https://www.cve.org/CVERecord?id=CVE-2026-71479 ----- Traducción: CVE-2026-71479 New… https://infoflow.cloud`

    Post summary

    The message cites CVE‑2026‑71479 with a brief mention of a user‑controlled image issue and a pre‑1.0.0‑rc.18 version, but it lacks a PoC, exploit, active‑use confirmation, patch guidance, or debunking claim.

    0000034
    100 followersView on X

Explore more