{"id":"CVE-2026-92719","summary":"Quickwit through 0.9.0 SSRF via SQS queue_url Parameter","details":"Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. Attackers can supply a malicious queue_url to the create-source API to scan internal networks and fingerprint services based on connection response differences.","modified":"2026-09-17T03:47:51.629977986Z","published":"2026-09-16T17:31:39.267Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92719.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-918"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92719.json"},{"type":"PACKAGE","url":"https://github.com/quickwit-oss/quickwit"},{"type":"ARTICLE","url":"https://github.com/quickwit-oss/quickwit/blob/v0.9.0/quickwit/quickwit-indexing/src/source/queue_sources/sqs_queue.rs#L230-L243"},{"type":"ARTICLE","url":"https://github.com/quickwit-oss/quickwit/blob/v0.9.0/quickwit/quickwit-serve/src/index_api/source_resource.rs#L56-L66"},{"type":"REPORT","url":"https://github.com/quickwit-oss/quickwit/issues/6703"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92719"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/quickwit-through-0.9.0-ssrf-via-sqs-queue-url-parameter"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/quickwit-oss/quickwit","events":[{"introduced":"0"},{"last_affected":"cc420c34d686a75f412b7cd450564c5c99ad6f21"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"0.9.0"}]}}],"versions":["v0.9.0","lambda-def4e26e9","def4e26e9","lambda-dd6442ea7","lambda-11587c00","qw-azure-20250812","qw-airmail-20250702","qw-airmail-20250603","qw-airmail-20250522","qw-airmail-20250529","qw-airmail-20250514-jemprof","qw-airmail-20250514","qw-airmail-20250430","qw-iridescent-20250415","qw-airmail-20250310","qw-airmail-20250109","qw-iridescent-20250128","qw-airmail-20241212","qw-airmail-20241128","qw-airmail-20241029","qw-airmail-20240919","qw-iridescent-20240906","qw-airmail-20240828","qw-airmail-20240826","qw-iridescent-20240802","qw-iridescent","qw-airmail-20240731","qw-airmail-20240716","qw-airmail-20240715","qw-fulmicoton-main-20240529","qw-fulmicoton-bisect-d71d","qw-fulmicoton-bisect-e5c14","qw-fulmicoton-bisect-ec502f03","qw-fulmicoton-bisect-e38b","qw-airmail-20240516","aws-lambda-beta-03","qw-airmail-20240425","qw-airmail-20240423","v0.8.0","qw-fulmicoton-21c","qw-fulmicoton-21b","qw-fumicoton-21-a","qw-meerkat","qw-airmail","aws-lambda-beta-02","v0.7.1","aws-lambda-beta-01","lambda-beta-01","qw-gcs","v0.7.0","v0.6.3","v0.6.2","v0.6.1","nightly","v0.6.0","v0.5.0","v0.5-pre","v0.4.0","happy-plazza","v0.3.1","v0.3.0","v0.3.0-pre","v0.2.1","v0.2.0","v0.1.0","0.1","v0.1.1","v0.1.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92719.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}