{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/quickwit/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:quickwit:quickwit:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-92719"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Quickwit (\u003c= 0.9.0)"],"_cs_severities":["high"],"_cs_tags":["ssrf","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["Quickwit"],"content_html":"\u003cp\u003eQuickwit versions through 0.9.0 are affected by a Server-Side Request Forgery (SSRF) vulnerability identified as CVE-2026-92719. The issue resides in the handling of the queue_url parameter within SQS file sources. The application fails to properly validate the host and scheme components of this parameter when processing requests via the create-source API. This flaw allows an unauthenticated attacker to force the Quickwit node to perform outbound requests to arbitrary internal IP addresses or domains. By analyzing the differential responses from the node, attackers can map internal infrastructure, perform port scanning, and fingerprint internal services that are not directly accessible from the internet. This vulnerability is particularly critical for deployments where the Quickwit instance resides within an internal network segment with access to sensitive management interfaces or other microservices.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-92719 enables unauthorized network reconnaissance within the host environment. By leveraging the Quickwit node as a proxy, attackers can bypass network access controls to interact with internal services. This leads to the exposure of internal service versions, identification of reachable assets, and potential precursor activity for further exploitation of internal-only APIs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of Quickwit to a version beyond 0.9.0 immediately to apply the patch for CVE-2026-92719.\u003c/li\u003e\n\u003cli\u003eImplement strict network egress filtering on all Quickwit nodes to limit connections to known-good SQS service endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous requests to the create-source API containing non-standard or internal URL schemes (e.g., file://, gopher://) or local IP ranges within the queue_url parameter.\u003c/li\u003e\n\u003cli\u003eEnsure that the service account running the Quickwit process follows the principle of least privilege, restricting its ability to communicate with internal network segments.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-16T19:52:15Z","date_published":"2026-09-16T19:52:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-quickwit-ssrf/","summary":"Quickwit versions through 0.9.0 contain a Server-Side Request Forgery vulnerability allowing unauthenticated attackers to perform internal network scanning and service fingerprinting via the create-source API.","title":"SSRF Vulnerability in Quickwit SQS File Source","url":"https://feed.craftedsignal.io/briefs/2026-09-quickwit-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Quickwit","version":"https://jsonfeed.org/version/1.1"}