PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108857 Hugging Face CVE debrief

Hugging Face Text Embeddings Inference through 1.9.4 contains a cleartext logging vulnerability that exposes the configured api_key because the router's Args struct lacks a redact attribute for it. Attackers with access to router logs, container output, or OTLP telemetry can recover the Bearer token and call the protected embedding and rerank endpoints.

Vendor
Hugging Face
Product
Text Embeddings Inference
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for Text Embeddings Inference deployments should assess exposure and take steps to mitigate the vulnerability. Defenders should prioritize verifying the presence of this vulnerability in their Text Embeddings Inference deployments and take steps to mitigate it. The cleartext logging vulnerability in Hugging Face Text Embeddings Inference through 1.9.4 exposes the configured api_key, allowing attackers to recover the Bearer token and

Why it matters

The cleartext logging vulnerability in Hugging Face Text Embeddings Inference through 1.9.4 exposes the configured api_key, allowing attackers to recover the Bearer token and call protected endpoints.

  • Attackers with access to router logs, container output, or OTLP telemetry can recover the Bearer token.
  • The recovered Bearer token can be used to call protected embedding and rerank endpoints.
  • Defenders should verify the presence of this vulnerability in their deployments and take steps to mitigate it.
  • Remediation priority is high for deployments with exposed router logs, container output, or OTLP telemetry.

Technical summary

The vulnerability exists in Hugging Face Text Embeddings Inference through 1.9.4 due to the lack of a redact attribute for the api_key in the router's Args struct, allowing attackers to recover the Bearer token and call protected endpoints. The recovered Bearer token can be used to call protected embedding and rerank endpoints. Defenders should prioritize verifying the presence of this vulnerability in their Text Embeddings Inference deployments and take steps to mitigate it. The cleartext logging vulnerability exposes the configured api_key, allowing attackers to recover the Bearer token.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their Text Embeddings Inference deployments and take steps to mitigate it.

Recommended defensive actions

  • Verify the presence of this vulnerability in Text Embeddings Inference deployments
  • Mitigate the vulnerability by updating to a fixed version
  • Monitor router logs, container output, and OTLP telemetry for potential exploitation
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details about the cleartext logging vulnerability in Hugging Face Text Embeddings Inference through 1.9.4. The vulnerability exists due to the lack of a redact attribute for the api_key in the router's Args struct, allowing attackers with access to router logs, container output, or OTLP telemetry to recover the Bearer token and call protected embedding and rerank endpoints. Defenders should verify the presence of this vulnerability in their deployments and take steps to mitigate it.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108857 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108857

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108857 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108857

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Hugging Face Text Embeddings Inference through 1.9.4 Cleartext API Key Logging

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108857.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/huggingface-text-embeddings-inference-api-key-startup-log

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/huggingface/text-embeddings-inference/blob/e80ef225ed0e6cb1717ce632a6a84b6cf211bb67/router/src/main.rs

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/huggingface/text-embeddings-inference

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/hugging-face-text-embeddings-inference-through-1.9.4-cleartext-api-key-logging

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.