CVE-2026-82909
Received Received - Intake

Session Expiration in QuantumNous new-api

Vulnerability report for CVE-2026-82909, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulDB

Description

A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
quantumnous new-api to 1.0.0-rc.15 (inc)
quantumnous new-api 1.0.0-rc.17

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects QuantumNous new-api up to version 1.0.0-rc.15. It involves a flaw in the Revoked API Token Handler component, specifically in the /api/usage/token/ file. An attacker can manipulate this component to cause session expiration. The issue is remotely exploitable and has been publicly disclosed.

Detection Guidance

Detecting this vulnerability requires checking if the affected component, QuantumNous new-api up to version 1.0.0-rc.15, is running on your system. Inspect the version of new-api installed and verify if the file /api/usage/token/ is present. Use commands like 'curl http://<target>/api/usage/token/' to check for the endpoint.

Impact Analysis

If exploited, this vulnerability could allow an attacker to force session expirations, potentially disrupting user sessions or forcing re-authentication. This may lead to inconvenience or service disruption for users relying on active sessions.

Mitigation Strategies

Upgrade QuantumNous new-api to version 1.0.0-rc.17 or later. Apply the patch 0d5995eb63f8801d32eb32fbe74b75b68752bfa9 to resolve the issue. Remove or restrict access to the /api/usage/token/ endpoint if upgrading is not immediately possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82909. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart