Low severity3.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108857
CVE-2026-108857
Description
Hugging Face Text Embeddings Inference through 1.9.4 contains a cleartext logging vulnerability that exposes the configured api_key because the router's Args struct lacks a redact attribute for it. Attackers with access to router logs, container output, or OTLP telemetry can recover the Bearer token and call the protected embedding and rerank endpoints.
Affected products
1- Range: <=1.9.4
Patches
Vulnerability mechanics
References
4- github.com/huggingface/text-embeddings-inference/blob/e80ef225ed0e6cb1717ce632a6a84b6cf211bb67/router/src/main.rsnvd
- github.com/huggingface/text-embeddings-inference/blob/e80ef225ed0e6cb1717ce632a6a84b6cf211bb67/router/src/main.rsnvd
- hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/huggingface-text-embeddings-inference-api-key-startup-lognvd
- www.vulncheck.com/advisories/hugging-face-text-embeddings-inference-through-1.9.4-cleartext-api-key-loggingnvd
News mentions
0No linked articles in our index yet.