THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8r8v-xf7q-rcpr (critical) — New API: Integer overflow in quota billing yields negative charges (self-crediting)

[GHSA] GHSA-8r8v-xf7q-rcpr (critical) — New API: Integer overflow in quota billing yields negative charges (self-crediting)

medgithub_advisoriesPublished 2026-08-17

GHSA-8r8v-xf7q-rcpr Severity: critical CVE: CVE-2026-71479

New API: Integer overflow in quota billing yields negative charges (self-crediting)

## Summary

Multiple billing paths multiplied **user-controlled quantity parameters** into the quota calculation without an upper bound or overflow-safe integer conversion. A crafted extreme value (e.g. image `n = 18446744073686646784`, a wrapped-negative

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8r8v-xf7q-rcpr