CVE-2026-82909
Deferred Deferred - Pending Action

Session Expiration in QuantumNous new-api

Vulnerability report for CVE-2026-82909, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-09-02

Assigner: VulDB

Description

A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-09-02
Generated
2026-09-21
AI Q&A
2026-09-01
EPSS Evaluated
2026-09-15
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
quantumnous new-api to 1.0.0-rc.15 (inc)
quantumnous new-api 1.0.0-rc.17

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects QuantumNous new-api up to version 1.0.0-rc.15. It involves a flaw in the Revoked API Token Handler component, specifically in the /api/usage/token/ file. An attacker can manipulate this component to cause session expiration. The issue is remotely exploitable and has been publicly disclosed.

Detection Guidance

Detecting this vulnerability requires checking if the affected component, QuantumNous new-api up to version 1.0.0-rc.15, is running on your system. Inspect the version of new-api installed and verify if the file /api/usage/token/ is present. Use commands like 'curl http://<target>/api/usage/token/' to check for the endpoint.

Impact Analysis

If exploited, this vulnerability could allow an attacker to force session expirations, potentially disrupting user sessions or forcing re-authentication. This may lead to inconvenience or service disruption for users relying on active sessions.

Compliance Impact

The vulnerability allows remote manipulation of session expiration via the Revoked API Token Handler in QuantumNous new-api up to 1.0.0-rc.15. This could potentially lead to unauthorized access or session hijacking, which may impact compliance with standards requiring session management controls such as GDPR (Article 32) or HIPAA (Security Rule). However, the specific impact on compliance depends on system configuration and deployment context.

Mitigation Strategies

Upgrade QuantumNous new-api to version 1.0.0-rc.17 or later. Apply the patch 0d5995eb63f8801d32eb32fbe74b75b68752bfa9 to resolve the issue. Remove or restrict access to the /api/usage/token/ endpoint if upgrading is not immediately possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82909. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart