PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108754 tbphp CVE debrief

GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.

Vendor
tbphp
Product
gpt-load
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for GPT-Load deployments, especially those with exposed logs or unauthorized access, should assess their exposure and prioritize remediation. This includes operators managing the system, platform administrators, vulnerability management teams, and security teams who need to verify and remediate this vulnerability to prevent proxy key exposure.

Why it matters

The cleartext logging vulnerability in GPT-Load through 1.4.11 exposes client proxy keys, allowing attackers to recover and use them. Defenders should prioritize verifying and remediating this vulnerability, especially in deployments with exposed logs or unauthorized access.

  • Attackers can recover proxy keys from logs and use them against the corresponding group
  • Defenders need to verify and remediate this vulnerability to prevent proxy key exposure
  • GPT-Load deployments with exposed logs or unauthorized access are at higher risk

Technical summary

The GPT-Load application through version 1.4.11 logs client proxy keys in cleartext due to the Gin Logger middleware recording the raw query string before the extractAuthKey function strips the key parameter. This vulnerability allows attackers with read access to console logs or the ./data/logs/app.log file to recover proxy keys from Gemini-style requests and use them against the corresponding group.

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability in GPT-Load deployments, especially those with exposed logs or unauthorized access.

Recommended defensive actions

  • Verify GPT-Load version and check if logs contain proxy keys
  • Restrict access to console logs and ./data/logs/app.log
  • Update GPT-Load to a version that fixes the cleartext logging vulnerability
  • Monitor logs for potential proxy key exposure
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the cleartext logging vulnerability in GPT-Load through 1.4.11. The vulnerability allows attackers with read access to console logs or ./data/logs/app.log to recover proxy keys.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108754 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108754

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108754 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108754

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • GPT-Load through 1.4.11 Cleartext Proxy Key Logging via Access Logger

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108754.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/@haind03/tbphp-gpt-load-proxy-key-access-log-disclosure

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/tbphp/gpt-load/blob/a12882be9e06011da5e0284db5dd4617a7ca6e6d/internal/middleware/middleware.go

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/tbphp/gpt-load

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/gpt-load-through-1.4.11-cleartext-proxy-key-logging-via-access-logger

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.