CVE-2026-82909: QuantumNous new-api Revoked API Token token session expiration
A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
QuantumNous new-api (Revoked API Token Handler)to a version that resolves this vulnerability.Fixed in 1.0.0-rc.17Patch 0d5995eb63f8801d32eb32fbe74b75b68752bfa9
Event History
Frequently Asked Questions
Which deployments are affected?
QuantumNous new-api versions up to and including 1.0.0-rc.15 are affected in an unknown portion of the Revoked API Token Handler associated with /api/usage/token/.
What access does an attacker need?
The attack can be performed remotely and requires low privileges. No user interaction is required.
What is the known impact?
Manipulation of the affected functionality can cause session expiration. The provided information indicates low confidentiality impact and no integrity or availability impact.
How should this be remediated?
Upgrade QuantumNous new-api to version 1.0.0-rc.17. The referenced patch is 0d5995eb63f8801d32eb32fbe74b75b68752bfa9.
Is exploitation likely?
A public exploit disclosure exists and may be used. The exploit maturity is rated as proof-of-concept.