github.comproduct
https://github.com/songquanpeng/one-api CVE-2026-11465
LOW
songquanpeng one-api Redemption Code Top-Up Endpoint redemption.go Redeem logic error
Record summary
CVE-2026-11465 has a selected CVSS score of 2.3 (low).
Description
A security flaw has been discovered in songquanpeng one-api up to 0.6.11-preview.7. Affected by this issue is the function Redeem of the file model/redemption.go of the component Redemption Code Top-Up Endpoint. The manipulation results in business logic errors. The attack may be launched remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 8, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 0.6.11-preview.0 | affected | |
| 0.6.11-preview.1 | affected | ||
| 0.6.11-preview.2 | affected | ||
| 0.6.11-preview.3 | affected | ||
| 0.6.11-preview.4 | affected | ||
| 0.6.11-preview.5 | affected | ||
| 0.6.11-preview.6 | affected | ||
| 0.6.11-preview.7 | affected | ||
github.com/songquanpeng/one-apiBrowse Go / github.com/songquanpeng/one-api | GitHub Advisory | 0.1.6-alpha to ≤ 0.6.11-preview.7 | affected |
References
8github.comexploitissue tracking
https://github.com/songquanpeng/one-api/issues/2397 github.comissue trackingpatch
https://github.com/songquanpeng/one-api/pull/2399 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-11465 CVE-2026-11465 | CVE Analysis and ReportThird-party advisory
https://vuldb.com/cve/CVE-2026-11465 Submit #833320 | songquanpeng oneapi v0.1.6-alpha(2023-04-26)– v0.6.11-preview.7(latest) Race ConditionThird-party advisory
https://vuldb.com/submit/833320 VDB-369085 | songquanpeng one-api Redemption Code Top-Up Endpoint redemption.go Redeem logic errorvdb entryTechnical description
https://vuldb.com/vuln/369085 VDB-369085 | CTI Indicators (IOB, IOC, IOA)signaturepermissions required
https://vuldb.com/vuln/369085/cti