CPE
Quickwit versions through 0.9.0 contain a Server-Side Request Forgery vulnerability allowing unauthenticated attackers to perform internal network scanning and service fingerprinting via the create-source API.