PT-2026-93882 · Git+1 · Quickwit

·

CVE-2026-92719

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Quickwit versions prior to 0.9.1
Description Insufficient validation of the host and scheme in the queue url parameter within SQS file sources allows an attacker to force the node to send requests to arbitrary internal addresses. By providing a malicious queue url to the 'create-source' API endpoint, an attacker can perform internal network scanning and fingerprint services by analyzing differences in connection responses.
Recommendations Update to a version newer than 0.9.0. Avoid using the queue url parameter in the 'create-source' API endpoint until the update is applied.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92719

Affected Products

Quickwit