Pterodactyl / Wings
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-61617 | Pterodactyl Wings SFTP write path does not enforce disk quota, allowing node-wide disk exhaustion | HIGH | 7.7 | Aug 26, 2026 |
| CVE-2026-52856 | Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service | HIGH | 7.5 | Jul 31, 2026 |
| CVE-2026-52855 | Wings exposes node configuration secrets through egg configuration-file templating | CRITICAL | 9.9 | Jul 31, 2026 |
| CVE-2026-52857 | Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM | MEDIUM | 5.5 | Jul 31, 2026 |
| CVE-2026-21696 | Endless reprocessing/reupload of activity log data due to SQLite max parameters limit not being considered | HIGH | 8.3 | Jan 19, 2026 |
| CVE-2025-69199 | Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstances | HIGH | 8.3 | Jan 19, 2026 |
| CVE-2025-68954 | Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced | HIGH | 7.5 | Jan 6, 2026 |
| CVE-2024-34066 | Arbitrary File Write/Read in Pterodactyl wings | HIGH | 8.5 | May 3, 2024 |
| CVE-2024-34068 | Server-side Request Forgery during remote file pull in Pterodactyl wings | MEDIUM | 6.4 | May 3, 2024 |
| CVE-2024-27102 | Improper isolation of server file access in github.com/pterodactyl/wings | CRITICAL | 10.0 | Mar 13, 2024 |
| CVE-2023-32080 | Wings vulnerable to escape to host from installation container | CRITICAL | 9.1 | May 10, 2023 |
| CVE-2023-25168 | Symbolic Link (Symlink) Following allowing the deletion of files and directories on the host system in wings | CRITICAL | 9.6 | Feb 8, 2023 |
| CVE-2023-25152 | Symbolic Link (Symlink) Following in github.com/pterodactyl/wings | HIGH | 8.8 | Feb 8, 2023 |
| CVE-2021-32699 | Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings | MEDIUM | 6.5 | Jun 22, 2021 |
Showing 1 to 14 of 14 CVEs