CVE-2026-33655

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomain disabled by default, URL validation checked domain allow/block rules but did not resolve a hostname and validate the resolved IP address, allowing authenticated users to configure Webhook, Bark, or Gotify notification URLs that point at an internal or metadata IP address. This issue is fixed in version 0.12.0-alpha.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:newapi:new_api:*:*:*:*:*:*:*:*

History

16 Jul 2026, 16:36

Type Values Removed Values Added
References () https://github.com/QuantumNous/new-api/commit/20399d3c8fcb4e3649d53163eb11940fd6763743 - () https://github.com/QuantumNous/new-api/commit/20399d3c8fcb4e3649d53163eb11940fd6763743 - Patch
References () https://github.com/QuantumNous/new-api/releases/tag/v0.12.0-alpha.1 - () https://github.com/QuantumNous/new-api/releases/tag/v0.12.0-alpha.1 - Release Notes
References () https://github.com/QuantumNous/new-api/security/advisories/GHSA-6qcr-qxgr-m7fv - () https://github.com/QuantumNous/new-api/security/advisories/GHSA-6qcr-qxgr-m7fv - Third Party Advisory
CPE cpe:2.3:a:newapi:new_api:*:*:*:*:*:*:*:*
First Time Newapi new Api
Newapi

09 Jul 2026, 23:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-09 23:17

Updated : 2026-07-16 16:36


NVD link : CVE-2026-33655

Mitre link : CVE-2026-33655

CVE.ORG link : CVE-2026-33655


JSON object : View

Products Affected

newapi

  • new_api
CWE
CWE-918

Server-Side Request Forgery (SSRF)