PatchSiren cyber security CVE debrief
CVE-2026-108754 tbphp CVE debrief
GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.
- Vendor
- tbphp
- Product
- gpt-load
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for GPT-Load deployments, especially those with exposed logs or unauthorized access, should assess their exposure and prioritize remediation. This includes operators managing the system, platform administrators, vulnerability management teams, and security teams who need to verify and remediate this vulnerability to prevent proxy key exposure.
Why it matters
The cleartext logging vulnerability in GPT-Load through 1.4.11 exposes client proxy keys, allowing attackers to recover and use them. Defenders should prioritize verifying and remediating this vulnerability, especially in deployments with exposed logs or unauthorized access.
- Attackers can recover proxy keys from logs and use them against the corresponding group
- Defenders need to verify and remediate this vulnerability to prevent proxy key exposure
- GPT-Load deployments with exposed logs or unauthorized access are at higher risk
Technical summary
The GPT-Load application through version 1.4.11 logs client proxy keys in cleartext due to the Gin Logger middleware recording the raw query string before the extractAuthKey function strips the key parameter. This vulnerability allows attackers with read access to console logs or the ./data/logs/app.log file to recover proxy keys from Gemini-style requests and use them against the corresponding group.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability in GPT-Load deployments, especially those with exposed logs or unauthorized access.
Recommended defensive actions
- Verify GPT-Load version and check if logs contain proxy keys
- Restrict access to console logs and ./data/logs/app.log
- Update GPT-Load to a version that fixes the cleartext logging vulnerability
- Monitor logs for potential proxy key exposure
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the cleartext logging vulnerability in GPT-Load through 1.4.11. The vulnerability allows attackers with read access to console logs or ./data/logs/app.log to recover proxy keys.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108754 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108754
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108754 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108754
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
GPT-Load through 1.4.11 Cleartext Proxy Key Logging via Access Logger
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108754.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@haind03/tbphp-gpt-load-proxy-key-access-log-disclosure
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/tbphp/gpt-load/blob/a12882be9e06011da5e0284db5dd4617a7ca6e6d/internal/middleware/middleware.go
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/tbphp/gpt-load
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/gpt-load-through-1.4.11-cleartext-proxy-key-logging-via-access-logger
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.