{"id":"CVE-2026-25591","aliases":["GHSA-w6x6-9fp7-fqm4","GO-2026-4531"],"url":"https://o3.security/vulnerability/CVE-2026-25591","summary":"New API has an SQL LIKE Wildcard Injection DoS via Token Search","details":"New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated users to cause denial of service through resource exhaustion by crafting malicious search patterns. The token search endpoint accepts user-supplied `keyword` and `token` parameters that are directly concatenated into SQL LIKE clauses without escaping wildcard characters (`%`, `_`). This allows attackers to inject patterns that trigger expensive database queries. Version 0.10.8-alpha.10 contains a patch.","published":"2026-02-24T00:41:30.198Z","modified":"2026-08-12T03:51:29.015013969Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/QuantumNous/new-api","fixedVersion":"0.10.8-alpha.10"}],"fix":{"url":"https://github.com/QuantumNous/new-api/commit/3e1be18310f35d20742683ca9e4bf3bcafc173c5","label":"QuantumNous/new-api@3e1be18"},"references":[{"type":"WEB","url":"https://github.com/QuantumNous/new-api/releases/tag/v0.10.8-alpha.10"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25591.json"},{"type":"ADVISORY","url":"https://github.com/QuantumNous/new-api/security/advisories/GHSA-w6x6-9fp7-fqm4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25591"},{"type":"FIX","url":"https://github.com/QuantumNous/new-api/commit/3e1be18310f35d20742683ca9e4bf3bcafc173c5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:29.015013969Z"}}