Cleartext Logging Vulnerability in Hugging Face Text Embeddings Inference
CVE-2026-108857

4.8MEDIUM

Key Information:

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108857?

The Hugging Face Text Embeddings Inference version 1.9.4 is susceptible to a cleartext logging vulnerability. This flaw arises from the absence of a redact attribute in the router's Args struct, which leads to the exposure of the configured api_key in logs. Attackers with access to these logs, container outputs, or OTLP telemetry can recover sensitive Bearer tokens, enabling them to access protected embedding and rerank endpoints. This vulnerability highlights the importance of securing log outputs and implementing robust data handling practices to safeguard API keys.

Affected Version(s)

Text Embeddings Inference 0 <= 1.9.4

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hieuPenguinnn
.