CVE-2026-33655: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filterin...

Added to the CISA Known Exploited Vulnerabilities catalog on 09 Jul 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 7.7.

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomain disabled by default, URL validation checked domain allow...

Required action: Review and patch if applicable to your AI infrastructure.