CVE-2026-64868: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo...

Added to the CISA Known Exploited Vulnerabilities catalog on 17 Aug 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 7.5.

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodies before signature validation in router/api-router.go and th...

Required action: Review and patch if applicable to your AI infrastructure.