Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 11 Oct 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hugging Face Text Embeddings Inference through 1.9.4 contains a cleartext logging vulnerability that exposes the configured api_key because the router's Args struct lacks a redact attribute for it. Attackers with access to router logs, container output, or OTLP telemetry can recover the Bearer token and call the protected embedding and rerank endpoints. | |
| Title | Hugging Face Text Embeddings Inference through 1.9.4 Cleartext API Key Logging | |
| Weaknesses | CWE-532 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T13:26:05.169Z
Reserved: 2026-10-11T13:06:45.431Z
Link: CVE-2026-108857
No data.
Status : Received
Published: 2026-10-11T14:17:05.503
Modified: 2026-10-11T14:17:05.503
Link: CVE-2026-108857
No data.
OpenCVE Enrichment
No data.
-
CWE-532
Insertion of Sensitive Information into Log File