Skip to content

Known CVE

New API < v0.12.10 - Stripe Webhook Bypass

New API < v0.12.10 contains a broken authentication caused by unauthenticated attacker forging Stripe webhook events, letting attackers credit arbitrary quota without payment, exploit requires no authentication.

CVE-2026-41432

High2026CVSS 7.1CWE-345

cve2026 · new-api · stripe · webhook · auth-bypass

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website