THREAT OPS › Threat News › [GHSA] GHSA-j6gc-4893-qwmp (medium) — New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
[GHSA] GHSA-j6gc-4893-qwmp (medium) — New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
GHSA-j6gc-4893-qwmp Severity: medium CVE: CVE-2026-64865
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
### Summary Authenticated users can repeatedly call PUT /api/user/self with language or sidebar_modules while relay requests are consuming quota. The settings path reads a full User snapshot and writes it back through User.Update(), which refreshes Redis w
Indicators of compromise
- CVE-2026-64865cve
Original source: https://github.com/advisories/GHSA-j6gc-4893-qwmp