Cleartext Logging Vulnerability in Hugging Face Text Embeddings Inference
CVE-2026-108857
4.8MEDIUM
What is CVE-2026-108857?
The Hugging Face Text Embeddings Inference version 1.9.4 is susceptible to a cleartext logging vulnerability. This flaw arises from the absence of a redact attribute in the router's Args struct, which leads to the exposure of the configured api_key in logs. Attackers with access to these logs, container outputs, or OTLP telemetry can recover sensitive Bearer tokens, enabling them to access protected embedding and rerank endpoints. This vulnerability highlights the importance of securing log outputs and implementing robust data handling practices to safeguard API keys.
Affected Version(s)
Text Embeddings Inference 0 <= 1.9.4
