Description
A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded.
Published: 2026-08-31
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Revoked API Token Handler of QuantumNous new‑api causes an attacker to force a session to expire by manipulating the /api/usage/token endpoint. The result is an unexpected loss of user authentication, disrupting normal service availability for legitimate users. The weakness is a session‑management issue (CWE‑613) that can be triggered remotely through crafted requests.

Affected Systems

QuantumNous new‑api component versions up to 1.0.0‑rc.15 are affected. Updating to 1.0.0‑rc.17 fixes the problem. No other software vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not in CISA KEV. The exploit is remote, relying on manipulation of authentication tokens via the exposed/unknown functionality at /api/usage/token. Because the flaw was publicly disclosed, it may be used by attackers seeking to disrupt user sessions.

Generated by OpenCVE AI on August 31, 2026 at 21:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade QuantumNous new-api to version 1.0.0‑rc.17, which contains the fix commit 0d5995eb63f8801d32eb32fbe74b75b68752bfa9.
  • If immediate upgrade is not possible, invalidate all current API tokens so any in‑use sessions are forced to re‑authenticate, mitigating the possibility of lingering valid sessions.
  • After applying the patch or token invalidation, review the Revoked API Token Handler configuration to ensure that session expiration is enforced automatically whenever a token is revoked, eliminating the remaining vulnerability window.

Generated by OpenCVE AI on August 31, 2026 at 21:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded.
Title QuantumNous new-api Revoked API Token token session expiration
First Time appeared Quantumnous
Quantumnous new-api
Weaknesses CWE-613
CPEs cpe:2.3:a:quantumnous:new-api:*:*:*:*:*:*:*:*
Vendors & Products Quantumnous
Quantumnous new-api
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Quantumnous New-api
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T20:30:09.755Z

Reserved: 2026-08-31T10:11:54.007Z

Link: CVE-2026-82909

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T21:17:54.677

Modified: 2026-08-31T21:17:54.677

Link: CVE-2026-82909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T21:45:04Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration