GHSA-rx45-hj8g-x4vmHighCVSS 7.5

Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. Attackers can supply a malicious queue_url to the create-source API to scan internal networks and fingerprint services based on connection response differences.

🔗 References (7)