securityonline.info 8/18/2026, 4:11:43 AM · external

CVE-2026-71479: New API Integer Overflow Exploited in the Wild

CVE-2026-71479: New API Integer Overflow Exploited in the Wild
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability (CVE-2026-71479) has been detected in the New API, an open-source AI gateway, allowing an integer overflow that enables users to exploit billing systems. The flaw can turn a small balance into a large one through crafted requests, leading to negative charges and potential service disruptions. The vulnerability, with a CVSS score of 9.1, was confirmed as actively exploited in the wild on July 6, 2026. Users are urged to upgrade to version 1.0.0-rc.18 or later to mitigate risks and review account activities for abnormal balance changes.

View Primary Source Via securityonline.info

Article by CyberSIXT