<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T15:54:10.565474+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-316828</id>
    <title>EUVD-2026-316828</title>
    <updated>2026-10-06T15:54:10.614360+00:00</updated>
    <content>EUVD-2026-316828</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-316828"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41432</id>
    <title>fkie_cve-2026-41432</title>
    <updated>2026-10-06T15:54:10.614398+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated attacker to forge webhook events and credit arbitrary quota to their account without making any payment. This issue has been patched in version 0.12.10.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41432"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xff3-5c9p-2mr4</id>
    <title>GHSA-xff3-5c9p-2mr4 — New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud</title>
    <updated>2026-10-06T15:54:10.614433+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/QuantumNous/new-api</p>
<p>## Summary</p>
<p>A critical vulnerability exists in the Stripe webhook handler that allows an **unauthenticated attacker to forge webhook events** and credit arbitrary quota to their account without making any payment. The vulnerability stems from three compounding flaws:</p>
<p>1. The Stripe webhook endpoint does not reject requests when `StripeWebhookSecret` is empty (the default).
2. When the HMAC secret is empty, any attacker can compute valid webhook signatures, effectively **bypassing signature verification entirely**.
3. The `Recharge` function does not validate that the order's `PaymentMethod` matches the callback source, enabling **cross-gateway exploitation** — an order created via any payment method (e.g., Epay) can be fulfilled through a forged Stripe webhook.</p>
<p>## Affected Components</p>
<p>- `controller/topup_stripe.go` — `StripeWebhook()`, `sessionCompleted()`
- `model/topup.go` — `Recharge()`, `RechargeCreem()`, `RechargeWaffo()`
- `controller/topup.go` — `EpayNotify()`
- `controller/topup_creem.go` — `CreemAdaptor.RequestPay()` (missing `PaymentMethod` field)
- `router/api-router.go` — webhook route registered without any guard</p>
<p>## CWE Classification</p>
<p>- **CWE-345**: Insufficient Verification of Data Authenticity
- **CWE-1188**: Initialization with an Insecure Default (empty webhook secret)
- **CWE-863**: Incorrect Authorization (cross-gateway order fulfillment)</p>
<p>## Vulnerability Details</p>
<p>### Flaw 1: Empty Webhook Secret Bypasses Signature Verification</p>
<p>The `StripeWebhookSecre…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xff3-5c9p-2mr4"/>
  </entry>
</feed>
