CVE-2026-108857
Hugging Face Text Embeddings Inference through 1.9.4 Cleartext API Key Logging
CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th
Hugging Face Text Embeddings Inference through 1.9.4 contains a cleartext logging vulnerability that exposes the configured api_key because the router's Args struct lacks a redact attribute for it. Attackers with access to router logs, container output, or OTLP telemetry can recover the Bearer token and call the protected embedding and rerank endpoints.
| CWE | CWE-532 |
| Vendor | hugging face |
| Product | text embeddings inference |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for hugging face text embeddings inference
Be the first to know when new low vulnerabilities affecting hugging face text embeddings inference are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
Hugging Face / Text Embeddings Inference
0 โค 1.9.4
References
hackmd.io: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/huggingface-text-embeddings-inference-api-key-startup-log github.com: https://github.com/huggingface/text-embeddings-inference/blob/e80ef225ed0e6cb1717ce632a6a84b6cf211bb67/router/src/main.rs#L170-L174 github.com: https://github.com/huggingface/text-embeddings-inference/blob/e80ef225ed0e6cb1717ce632a6a84b6cf211bb67/router/src/main.rs#L204-L216 github.com: https://github.com/huggingface/text-embeddings-inference vulncheck.com: https://www.vulncheck.com/advisories/hugging-face-text-embeddings-inference-through-1.9.4-cleartext-api-key-logging
Credits
hieuPenguinnn