Executive brief
New API has an SQL LIKE Wildcard Injection DoS via Token Search in github.com/QuantumNous/new-api
Affected products
- Go github.com/QuantumNous/new-api
Junglewise Threat Intelligence
CVE-2026-25591 · Severity: medium · CVSS 4 · Published 2026-02-25
Technologies: github.com/QuantumNous/new-api (Go). Vendors: Go.
New API has an SQL LIKE Wildcard Injection DoS via Token Search in github.com/QuantumNous/new-api