CVE-2026-42339: CWE-918: Server-Side Request Forgery (SSRF) in QuantumNous new-api
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6 (CVE-2025-62155) does not block the unspecified address 0.0.0.0. A regular (non-admin) user holding any valid API token can send a multimodal request to /v1/chat/completions, /v1/responses, or /v1/messages with 0.0.0.0 as the image/file URL host, bypassing the private-IP filter and causing the server to issue HTTP requests to localhost. This constitutes at minimum a blind SSRF; when the request is routed through an AWS/Bedrock Claude adaptor, the fetched content is inlined into the model response, upgrading it to a full-read SSRF. At time of publication, there are no publicly available patches.
AI Analysis
Technical Summary
QuantumNous new-api (versions up to 0.11.9-alpha.1) contains an SSRF vulnerability due to incomplete filtering of the unspecified IP address 0.0.0.0. This allows authenticated users with any valid API token to bypass private IP filters by specifying 0.0.0.0 as the host in multimodal requests to certain API endpoints. The server then issues HTTP requests to localhost, potentially exposing internal resources. When requests are processed through an AWS/Bedrock Claude adaptor, the vulnerability escalates to a full-read SSRF by inlining fetched content into AI model responses. The vulnerability is tracked as CVE-2026-42339 with a CVSS 4.0 score of 7.1 (high severity). The product is cloud-hosted, and vendor-managed remediation is expected, though no detailed patch information is currently public.
Potential Impact
The vulnerability enables authenticated users with any valid API token to induce the server to make HTTP requests to localhost by specifying 0.0.0.0 as the target host. This can lead to blind SSRF attacks, potentially allowing attackers to interact with internal services not normally accessible externally. When integrated with the AWS/Bedrock Claude adaptor, the attack can escalate to full-read SSRF, where the attacker can obtain the content fetched by the server and have it included in AI model responses. This could expose sensitive internal data or services. No known exploits are reported in the wild at the time of publication.
Mitigation Recommendations
Since the product is a cloud service, remediation is managed by the vendor. Although a patch is indicated as available, no public patch details or official fixes are currently provided. Security teams should monitor vendor advisories for updates and apply patches or mitigations as soon as they become available. In the interim, review API token usage and restrict token distribution to trusted users to reduce risk exposure.
CVE-2026-42339: CWE-918: Server-Side Request Forgery (SSRF) in QuantumNous new-api
Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6 (CVE-2025-62155) does not block the unspecified address 0.0.0.0. A regular (non-admin) user holding any valid API token can send a multimodal request to /v1/chat/completions, /v1/responses, or /v1/messages with 0.0.0.0 as the image/file URL host, bypassing the private-IP filter and causing the server to issue HTTP requests to localhost. This constitutes at minimum a blind SSRF; when the request is routed through an AWS/Bedrock Claude adaptor, the fetched content is inlined into the model response, upgrading it to a full-read SSRF. At time of publication, there are no publicly available patches.
CVSS v4.0
Score 7.1high
Affected software
pkg:github/quantumnous/new-apiRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
QuantumNous new-api (versions up to 0.11.9-alpha.1) contains an SSRF vulnerability due to incomplete filtering of the unspecified IP address 0.0.0.0. This allows authenticated users with any valid API token to bypass private IP filters by specifying 0.0.0.0 as the host in multimodal requests to certain API endpoints. The server then issues HTTP requests to localhost, potentially exposing internal resources. When requests are processed through an AWS/Bedrock Claude adaptor, the vulnerability escalates to a full-read SSRF by inlining fetched content into AI model responses. The vulnerability is tracked as CVE-2026-42339 with a CVSS 4.0 score of 7.1 (high severity). The product is cloud-hosted, and vendor-managed remediation is expected, though no detailed patch information is currently public.
Potential Impact
The vulnerability enables authenticated users with any valid API token to induce the server to make HTTP requests to localhost by specifying 0.0.0.0 as the target host. This can lead to blind SSRF attacks, potentially allowing attackers to interact with internal services not normally accessible externally. When integrated with the AWS/Bedrock Claude adaptor, the attack can escalate to full-read SSRF, where the attacker can obtain the content fetched by the server and have it included in AI model responses. This could expose sensitive internal data or services. No known exploits are reported in the wild at the time of publication.
Mitigation Recommendations
Since the product is a cloud service, remediation is managed by the vendor. Although a patch is indicated as available, no public patch details or official fixes are currently provided. Security teams should monitor vendor advisories for updates and apply patches or mitigations as soon as they become available. In the interim, review API token usage and restrict token distribution to trusted users to reduce risk exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-26T13:26:14.514Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
- Is Cloud Service
- true
Threat ID: 69fe68edcbff5d861039d871
Added to database: 05/08/2026, 22:51:25 UTC
Last enriched: 05/16/2026, 10:53:42 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 160
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.