PatchSiren cyber security CVE debrief
CVE-2026-108857 Hugging Face CVE debrief
Hugging Face Text Embeddings Inference through 1.9.4 contains a cleartext logging vulnerability that exposes the configured api_key because the router's Args struct lacks a redact attribute for it. Attackers with access to router logs, container output, or OTLP telemetry can recover the Bearer token and call the protected embedding and rerank endpoints.
- Vendor
- Hugging Face
- Product
- Text Embeddings Inference
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for Text Embeddings Inference deployments should assess exposure and take steps to mitigate the vulnerability. Defenders should prioritize verifying the presence of this vulnerability in their Text Embeddings Inference deployments and take steps to mitigate it. The cleartext logging vulnerability in Hugging Face Text Embeddings Inference through 1.9.4 exposes the configured api_key, allowing attackers to recover the Bearer token and
Why it matters
The cleartext logging vulnerability in Hugging Face Text Embeddings Inference through 1.9.4 exposes the configured api_key, allowing attackers to recover the Bearer token and call protected endpoints.
- Attackers with access to router logs, container output, or OTLP telemetry can recover the Bearer token.
- The recovered Bearer token can be used to call protected embedding and rerank endpoints.
- Defenders should verify the presence of this vulnerability in their deployments and take steps to mitigate it.
- Remediation priority is high for deployments with exposed router logs, container output, or OTLP telemetry.
Technical summary
The vulnerability exists in Hugging Face Text Embeddings Inference through 1.9.4 due to the lack of a redact attribute for the api_key in the router's Args struct, allowing attackers to recover the Bearer token and call protected endpoints. The recovered Bearer token can be used to call protected embedding and rerank endpoints. Defenders should prioritize verifying the presence of this vulnerability in their Text Embeddings Inference deployments and take steps to mitigate it. The cleartext logging vulnerability exposes the configured api_key, allowing attackers to recover the Bearer token.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their Text Embeddings Inference deployments and take steps to mitigate it.
Recommended defensive actions
- Verify the presence of this vulnerability in Text Embeddings Inference deployments
- Mitigate the vulnerability by updating to a fixed version
- Monitor router logs, container output, and OTLP telemetry for potential exploitation
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details about the cleartext logging vulnerability in Hugging Face Text Embeddings Inference through 1.9.4. The vulnerability exists due to the lack of a redact attribute for the api_key in the router's Args struct, allowing attackers with access to router logs, container output, or OTLP telemetry to recover the Bearer token and call protected embedding and rerank endpoints. Defenders should verify the presence of this vulnerability in their deployments and take steps to mitigate it.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108857 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108857
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108857 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108857
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Hugging Face Text Embeddings Inference through 1.9.4 Cleartext API Key Logging
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108857.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/huggingface-text-embeddings-inference-api-key-startup-log
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/huggingface/text-embeddings-inference/blob/e80ef225ed0e6cb1717ce632a6a84b6cf211bb67/router/src/main.rs
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/huggingface/text-embeddings-inference
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/hugging-face-text-embeddings-inference-through-1.9.4-cleartext-api-key-logging
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.