๐Ÿ” CVE Alert

CVE-2026-108857

LOW 3.3

Hugging Face Text Embeddings Inference through 1.9.4 Cleartext API Key Logging

CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th

Hugging Face Text Embeddings Inference through 1.9.4 contains a cleartext logging vulnerability that exposes the configured api_key because the router's Args struct lacks a redact attribute for it. Attackers with access to router logs, container output, or OTLP telemetry can recover the Bearer token and call the protected embedding and rerank endpoints.

CWE CWE-532
Vendor hugging face
Product text embeddings inference
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for hugging face text embeddings inference

Be the first to know when new low vulnerabilities affecting hugging face text embeddings inference are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

Hugging Face / Text Embeddings Inference
0 โ‰ค 1.9.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/huggingface-text-embeddings-inference-api-key-startup-log github.com: https://github.com/huggingface/text-embeddings-inference/blob/e80ef225ed0e6cb1717ce632a6a84b6cf211bb67/router/src/main.rs#L170-L174 github.com: https://github.com/huggingface/text-embeddings-inference/blob/e80ef225ed0e6cb1717ce632a6a84b6cf211bb67/router/src/main.rs#L204-L216 github.com: https://github.com/huggingface/text-embeddings-inference vulncheck.com: https://www.vulncheck.com/advisories/hugging-face-text-embeddings-inference-through-1.9.4-cleartext-api-key-logging

Credits

hieuPenguinnn