Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded. | |
| Title | QuantumNous new-api Revoked API Token token session expiration | |
| First Time appeared |
Quantumnous
Quantumnous new-api |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:quantumnous:new-api:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Quantumnous
Quantumnous new-api |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-31T20:30:09.755Z
Reserved: 2026-08-31T10:11:54.007Z
Link: CVE-2026-82909
No data.
Status : Received
Published: 2026-08-31T21:17:54.677
Modified: 2026-08-31T21:17:54.677
Link: CVE-2026-82909
No data.
OpenCVE Enrichment
Updated: 2026-08-31T21:45:04Z
-
CWE-613
Insufficient Session Expiration