{"schema_version":"1.7.3","id":"GO-2026-4531","published":"2026-02-25T23:07:04Z","modified":"2026-02-25T23:40:58.977199Z","aliases":["CVE-2026-25591","GHSA-w6x6-9fp7-fqm4"],"summary":"New API has an SQL LIKE Wildcard Injection DoS via Token Search in github.com/QuantumNous/new-api","details":"New API has an SQL LIKE Wildcard Injection DoS via Token Search in github.com/QuantumNous/new-api","affected":[{"package":{"name":"github.com/QuantumNous/new-api","ecosystem":"Go","purl":"pkg:golang/github.com/QuantumNous/new-api"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.10.8-alpha.10"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-4531.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/QuantumNous/new-api/security/advisories/GHSA-w6x6-9fp7-fqm4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25591"},{"type":"FIX","url":"https://github.com/QuantumNous/new-api/commit/3e1be18310f35d20742683ca9e4bf3bcafc173c5"},{"type":"WEB","url":"https://github.com/QuantumNous/new-api/releases/tag/v0.10.8-alpha.10"}],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-4531"}}