<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:40:18 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-316828</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-316828</link>
      <description>EUVD-2026-316828</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-316828</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41432</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41432</link>
      <description>&lt;p&gt;New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated attacker to forge webhook events and credit arbitrary quota to their account without making any payment. This issue has been patched in version 0.12.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated attacker to forge webhook events and credit arbitrary quota to their account without making any payment. This issue has been patched in version 0.12.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41432</guid>
    </item>
    <item>
      <title>GHSA-xff3-5c9p-2mr4 — New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xff3-5c9p-2mr4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/QuantumNous/new-api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A critical vulnerability exists in the Stripe webhook handler that allows an **unauthenticated attacker to forge webhook events** and credit arbitrary quota to their account without making any payment. The vulnerability stems from three compounding flaws:&lt;/p&gt;
&lt;p&gt;1. The Stripe webhook endpoint does not reject requests when `StripeWebhookSecret` is empty (the default).
2. When the HMAC secret is empty, any attacker can compute valid webhook signatures, effectively **bypassing signature verification entirely**.
3. The `Recharge` function does not validate that the order&amp;#39;s `PaymentMethod` matches the callback source, enabling **cross-gateway exploitation** — an order created via any payment method (e.g., Epay) can be fulfilled through a forged Stripe webhook.&lt;/p&gt;
&lt;p&gt;## Affected Components&lt;/p&gt;
&lt;p&gt;- `controller/topup_stripe.go` — `StripeWebhook()`, `sessionCompleted()`
- `model/topup.go` — `Recharge()`, `RechargeCreem()`, `RechargeWaffo()`
- `controller/topup.go` — `EpayNotify()`
- `controller/topup_creem.go` — `CreemAdaptor.RequestPay()` (missing `PaymentMethod` field)
- `router/api-router.go` — webhook route registered without any guard&lt;/p&gt;
&lt;p&gt;## CWE Classification&lt;/p&gt;
&lt;p&gt;- **CWE-345**: Insufficient Verification of Data Authenticity
- **CWE-1188**: Initialization with an Insecure Default (empty webhook secret)
- **CWE-863**: Incorrect Authorization (cross-gateway order fulfillment)&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Flaw 1: Empty Webhook Secret Bypasses Signature Verification&lt;/p&gt;
&lt;p&gt;The `StripeWebhookSecre…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/QuantumNous/new-api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A critical vulnerability exists in the Stripe webhook handler that allows an **unauthenticated attacker to forge webhook events** and credit arbitrary quota to their account without making any payment. The vulnerability stems from three compounding flaws:&lt;/p&gt;
&lt;p&gt;1. The Stripe webhook endpoint does not reject requests when `StripeWebhookSecret` is empty (the default).
2. When the HMAC secret is empty, any attacker can compute valid webhook signatures, effectively **bypassing signature verification entirely**.
3. The `Recharge` function does not validate that the order&amp;#39;s `PaymentMethod` matches the callback source, enabling **cross-gateway exploitation** — an order created via any payment method (e.g., Epay) can be fulfilled through a forged Stripe webhook.&lt;/p&gt;
&lt;p&gt;## Affected Components&lt;/p&gt;
&lt;p&gt;- `controller/topup_stripe.go` — `StripeWebhook()`, `sessionCompleted()`
- `model/topup.go` — `Recharge()`, `RechargeCreem()`, `RechargeWaffo()`
- `controller/topup.go` — `EpayNotify()`
- `controller/topup_creem.go` — `CreemAdaptor.RequestPay()` (missing `PaymentMethod` field)
- `router/api-router.go` — webhook route registered without any guard&lt;/p&gt;
&lt;p&gt;## CWE Classification&lt;/p&gt;
&lt;p&gt;- **CWE-345**: Insufficient Verification of Data Authenticity
- **CWE-1188**: Initialization with an Insecure Default (empty webhook secret)
- **CWE-863**: Incorrect Authorization (cross-gateway order fulfillment)&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Flaw 1: Empty Webhook Secret Bypasses Signature Verification&lt;/p&gt;
&lt;p&gt;The `StripeWebhookSecre…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xff3-5c9p-2mr4</guid>
    </item>
  </channel>
</rss>
