# New API: quota arithmetic is part of the trust boundary

An admission check and final bill can disagree even when both work in ordinary examples. Numeric bounds, rounding and the sign of the final ledger entry deserve the same scrutiny as authentication.

## What deployment does this concern?

**Component and scope:** Quota settlement in affected New API release candidates.

**Affected versions / scope:** ≤ 1.0.0-rc.17

**Vendor remediation:** ≥ 1.0.0-rc.18

The caller must satisfy normal pre-consumption requirements through a positive balance or valid subscription. Integer overflow during settlement can then turn a charge into a credit. Self-registration with free credits increases exposure when configured.

## Vendor response and practical action

The vendor reports exploitation observed on 6 July and an emergency fix on 7 July, with the advisory published on 9 July. rc.18 is the stated patch; rc.19 adds logging context. Preserve the release-candidate qualifier.

Treat the vendor notice as the starting point for an applicability decision. Identify the installed artifact and configuration, document whether the prerequisite exists, and assign an owner to any required change. A public advisory does not establish that your installation was exposed or that a managed service shares the same condition.

## What clients can learn

Evaluate the ledger as a state transition: reserve, dispatch, settle or release. Concurrency, very large usage values, cancellation and repeated settlement should not create spendable credit.

A useful evaluation result connects a named control to evidence from the actual deployment. Keep the provider's statement, your effective configuration and a relevant demonstration together. If the result depends on a feature being disabled or a network being isolated, retain that fact with the version number so a later change triggers review.

## Questions to take to your provider

- What upper bounds apply to tokens, prices and multiplication?
- Is the reservation atomic under competing requests?
- Can a failed or repeated settlement increase a user's balance?
- How are anomalous credits reconciled with provider invoices?

Use the [six-page evaluation worksheet](/assets/downloads/ai-gateway-evaluation-worksheet.pdf) to record evidence, ownership and actions. Continue with [AI gateway budgets and scaling: measure the whole request](/resources/ai-gateway-budgets-and-scaling) for the wider evaluation context.

### Technical detail: evidence and identifier limits

The finding belongs to New API. It must not be assigned to the separate One API project merely because the projects share naming conventions.



Evidence label: **security advisory**. Source-review date: **2026-10-07**. Source publication or event date: **2026-07-09**. These dates do not change merely because this article is rebuilt.

## Primary sources

- [GHSA-8r8v-xf7q-rcpr · vendor advisory](https://github.com/QuantumNous/new-api/security/advisories/GHSA-8r8v-xf7q-rcpr)


---
Published: 2026-10-07. Modified: 2026-10-07. Sources reviewed: 2026-10-07.

Author: OneQuill Research. Affiliation: OneQuill develops OneVir. Documentary review; selected case totals are not vendor security rankings.
