VYPR

text-embeddings-inference

by Huggingface

CVEs (1)

  • CVE-2026-108857LowOct 11, 2026
    risk 0.14cvss 3.3epss —

    Hugging Face Text Embeddings Inference through 1.9.4 contains a cleartext logging vulnerability that exposes the configured api_key because the router's Args struct lacks a redact attribute for it. Attackers with access to router logs, container output, or OTLP telemetry can…