THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-j6gc-4893-qwmp (medium) — New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass

[GHSA] GHSA-j6gc-4893-qwmp (medium) — New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass

medgithub_advisoriesPublished 2026-08-17

GHSA-j6gc-4893-qwmp Severity: medium CVE: CVE-2026-64865

New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass

### Summary Authenticated users can repeatedly call PUT /api/user/self with language or sidebar_modules while relay requests are consuming quota. The settings path reads a full User snapshot and writes it back through User.Update(), which refreshes Redis w

Indicators of compromise

Original source: https://github.com/advisories/GHSA-j6gc-4893-qwmp