THREAT OPS › Threat News › [GHSA] GHSA-8r8v-xf7q-rcpr (critical) — New API: Integer overflow in quota billing yields negative charges (self-crediting)
[GHSA] GHSA-8r8v-xf7q-rcpr (critical) — New API: Integer overflow in quota billing yields negative charges (self-crediting)
GHSA-8r8v-xf7q-rcpr Severity: critical CVE: CVE-2026-71479
New API: Integer overflow in quota billing yields negative charges (self-crediting)
## Summary
Multiple billing paths multiplied **user-controlled quantity parameters** into the quota calculation without an upper bound or overflow-safe integer conversion. A crafted extreme value (e.g. image `n = 18446744073686646784`, a wrapped-negative
Indicators of compromise
- CVE-2026-71479cve
Original source: https://github.com/advisories/GHSA-8r8v-xf7q-rcpr