New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated users to cause denial of service through resource exhaustion by crafting malicious search patterns. The token search endpoint accepts user-supplied `keyword` and `token` parameters that are directly concatenated into SQL LIKE clauses without escaping wildcard characters (`%`, `_`). This allows attackers to inject patterns that trigger expensive database queries. Version 0.10.8-alpha.10 contains a patch.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Newapi
Newapi new Api |
|
| CPEs | cpe:2.3:a:newapi:new_api:*:*:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha1:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha2:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha3:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha4:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha5:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha6:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha7:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha8:*:*:*:*:*:* cpe:2.3:a:newapi:new_api:0.10.8:alpha9:*:*:*:*:*:* |
|
| Vendors & Products |
Newapi
Newapi new Api |
|
| Metrics |
cvssV3_1
|
Thu, 26 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Feb 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quantumnous
Quantumnous new-api |
|
| Vendors & Products |
Quantumnous
Quantumnous new-api |
Tue, 24 Feb 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated users to cause denial of service through resource exhaustion by crafting malicious search patterns. The token search endpoint accepts user-supplied `keyword` and `token` parameters that are directly concatenated into SQL LIKE clauses without escaping wildcard characters (`%`, `_`). This allows attackers to inject patterns that trigger expensive database queries. Version 0.10.8-alpha.10 contains a patch. | |
| Title | New API has an SQL LIKE Wildcard Injection DoS via Token Search | |
| Weaknesses | CWE-943 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-02-24T00:41:30.198Z
Updated: 2026-02-26T14:57:18.199Z
Reserved: 2026-02-03T01:02:46.716Z
Link: CVE-2026-25591
Updated: 2026-02-26T14:57:12.150Z
Status : Analyzed
Published: 2026-02-24T01:16:13.457
Modified: 2026-03-03T17:22:36.210
Link: CVE-2026-25591
No data.