Junglewise Threat Intelligence

CVE-2026-63086: Hugging Face text-generation-inference SSRF in multimodal chat endpoint

CVE-2026-63086 · Severity: high · CVSS 8.6 · Published 2026-07-16

Vendors: Hugging Face.

Executive brief

Hugging Face Text Generation Inference (TGI) is a toolkit for deploying and serving large language models. A security flaw in its multimodal chat feature allows an unauthenticated attacker to force the server to make unauthorized web requests to internal systems. This could lead to the exposure of sensitive internal data, such as cloud service credentials or private network information, potentially compromising the entire infrastructure where the model is hosted.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `fetch_image` function within `router/src/validation.rs` of text-generation-inference (TGI). The application fails to validate the target host of an `image_url` provided in a multimodal chat request, allowing requests to loopback, private (RFC1918), and cloud metadata addresses (e.g., 169.254.169.254). Furthermore, the underlying `reqwest` HTTP client is configured to follow redirects by default, allowing attackers to bypass basic scheme checks via a redirect chain from an external HTTPS URL to an internal HTTP resource. An unauthenticated remote attacker can exploit this to perform internal port scanning or steal cloud environment credentials. The repository was archived in March 2026, and users are advised to implement network-level egress filtering or migrate to supported alternatives.

Affected products

  • Hugging Face text-generation-inference through 3.3.7

Timeline

  • 2026-03-21: other: Repository archived by owner
  • 2026-07-16: disclosed: Vulnerability disclosed by VulnCheck and researcher George Chen
  • 2026-07-16: advisory

References