What is CVE-2026-64865?
The New API LLM gateway has a race condition vulnerability in the `PUT /api/user/self` endpoint, affecting versions prior to 1.0.0-rc.16. Repeated requests updating language or `sidebar_modules` can race relay billing due to the `controller/user.go` calling `User.Update` and `updateUserCache` incorrectly. Affected users should immediately upgrade to version 1.0.0-rc.16 or later.
Azərbaycanca: New API LLM şlyuzu 1.0.0-rc.16 versiyasına qədər `PUT /api/user/self` endpointində `race condition` zəifliyinə malikdir. Bu, dil və ya `sidebar_modules` yeniləmələri zamanı təkrarlanan sorğular vastəsilə billing hesablamalarında yanlışlıqlara səbəb ola bilər. Təsirə məruz qalan istifadəçilər dərhal 1.0.0-rc.16 və ya daha yuxarı versiyaya yeniləməlidir.
FAQ2
Which versions of the New API LLM gateway are affected by CVE-2026-64865?
All versions prior to 1.0.0-rc.16 are affected.
How can I protect against CVE-2026-64865?
You should immediately upgrade to version 1.0.0-rc.16 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.