Description
Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. Attackers can supply a malicious queue_url to the create-source API to scan internal networks and fingerprint services based on connection response differences.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Server-Side Request Forgery
Action: Immediate Patch
AI Analysis

Impact

Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. The flaw, identified as CWE-918, enables an attacker to supply a malicious queue_url to the create-source API, which can be used to probe internal networks and fingerprint services based on connection responses. This leads to a loss of confidentiality for internal resources and could serve as a stepping stone for further exploitation.

Affected Systems

The vulnerability affects the open-source Quickwit (oss) product released through version 0.9.0 and earlier. Any deployment of Quickwit that exposes the create-source API to untrusted users is susceptible, regardless of the operating system or cloud provider. The issue is documented in Quickwit OSS source repositories and tracks.

Risk and Exploitability

The CVSS score of 8.7 classifies this as High severity. The EPSS score of under 1% indicates that active exploitation is currently rare, but the lack of a KEV listing does not reduce risk for environments where Quickwit is exposed. Attackers can mount this attack from any system that can call the exposed API, making it feasible with remote access. Exploitation requires the ability to submit a source creation request; no special privileges beyond API access are needed. The impact is limited to internal network reconnaissance, but could assist in more damaging attacks if the attacker later gains privileged access.

Generated by OpenCVE AI on September 18, 2026 at 06:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Quickwit to a version newer than 0.9.0 that validates the queue_url parameter.
  • If an upgrade is impossible, restrict the create-source API to trusted administrators only and/or enforce a whitelist of allowed SQS queue URLs to prevent arbitrary host access.
  • Place the Quickwit instance behind a firewall or network segmentation that blocks outbound traffic to internal addresses, eliminating the attacker’s ability to use SSRF to reach internal services.

Generated by OpenCVE AI on September 18, 2026 at 06:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Quickwit-oss
Quickwit-oss quickwit
Vendors & Products Quickwit-oss
Quickwit-oss quickwit

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. Attackers can supply a malicious queue_url to the create-source API to scan internal networks and fingerprint services based on connection response differences.
Title Quickwit through 0.9.0 SSRF via SQS queue_url Parameter
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Quickwit-oss Quickwit
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:53.668Z

Reserved: 2026-09-16T17:20:10.837Z

Link: CVE-2026-92719

cve-icon Vulnrichment

Updated: 2026-09-16T17:48:21.186Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T18:17:22.837

Modified: 2026-09-24T20:47:31.797

Link: CVE-2026-92719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:12:14Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)