Low severity3.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108754
CVE-2026-108754
Description
GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/tbphp/gpt-load/blob/a12882be9e06011da5e0284db5dd4617a7ca6e6d/internal/middleware/middleware.gonvd
- github.com/tbphp/gpt-load/blob/a12882be9e06011da5e0284db5dd4617a7ca6e6d/internal/middleware/middleware.gonvd
- hackmd.io/@haind03/tbphp-gpt-load-proxy-key-access-log-disclosurenvd
- www.vulncheck.com/advisories/gpt-load-through-1.4.11-cleartext-proxy-key-logging-via-access-loggernvd
News mentions
0No linked articles in our index yet.