Insecure Default Initialization of Resource Affecting github.com/quantumnous/new-api/controller package, versions <0.12.10


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.85% (56th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMQUANTUMNOUSNEWAPICONTROLLER-16415117
  • published4 May 2026
  • disclosed24 Apr 2026
  • creditChangeYu0229

Introduced: 24 Apr 2026

CVE-2026-41432  (opens in a new tab)
CWE-1188  (opens in a new tab)
CWE-345  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade github.com/QuantumNous/new-api/controller to version 0.12.10 or higher.

Overview

Affected versions of this package are vulnerable to Insecure Default Initialization of Resource via the StripeWebhook process. An attacker can gain unauthorized quota credits and perform financial fraud by forging webhook requests with a publicly computable signature when the webhook secret is left empty, and by exploiting insufficient validation of the payment method and payment status fields. This is only exploitable if any payment method is configured and the webhook secret remains unset.

Workaround

This vulnerability can be mitigated by setting the webhook secret to any non-empty value and/or blocking the webhook endpoint if Stripe is not in use.

CVSS Base Scores

version 4.0
version 3.1