Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w6x6-9fp7-fqm4 | New API has an SQL LIKE Wildcard Injection DoS via Token Search |
Tue, 03 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Newapi
Newapi new Api |
|
| CPEs | cpe:2.3:a:newapi:new_api:*:*:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha1:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha2:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha3:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha4:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha5:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha6:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha7:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha8:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha9:*:*:*:*:*:* |
|
| Vendors & Products |
Newapi
Newapi new Api |
|
| Metrics |
cvssV3_1
|
Thu, 26 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Feb 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quantumnous
Quantumnous new-api |
|
| Vendors & Products |
Quantumnous
Quantumnous new-api |
Tue, 24 Feb 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated users to cause denial of service through resource exhaustion by crafting malicious search patterns. The token search endpoint accepts user-supplied `keyword` and `token` parameters that are directly concatenated into SQL LIKE clauses without escaping wildcard characters (`%`, `_`). This allows attackers to inject patterns that trigger expensive database queries. Version 0.10.8-alpha.10 contains a patch. | |
| Title | New API has an SQL LIKE Wildcard Injection DoS via Token Search | |
| Weaknesses | CWE-943 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-26T14:57:18.199Z
Reserved: 2026-02-03T01:02:46.716Z
Link: CVE-2026-25591
Updated: 2026-02-26T14:57:12.150Z
Status : Analyzed
Published: 2026-02-24T01:16:13.457
Modified: 2026-03-03T17:22:36.210
Link: CVE-2026-25591
No data.
OpenCVE Enrichment
Updated: 2026-04-17T16:15:22Z
Github GHSA