github.com/pterodactyl/wings
Go14 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/pterodactyl/wingspage 1 of 1
- CVE-2021-32699MEDIUMCVSS 6.5EG 6.5fixed in 1.4.42021-06-22
Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prior to `1.4.4` are vulnerable to system resource exhaustion due to improper container process limits being defi…
- CVE-2023-25152HIGHCVSS 8.4EG 8.4fixed in 1.7.3 or 1.11.3, by version range2023-02-08
Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on the host system that previously did not exist, potentially allowing attackers t…
- CVE-2023-25168CRITICALCVSS 9.6EG 9.6fixed in 1.7.4 or 1.11.4, by version range2023-02-09
Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vulnerability can be combined with `GHSA-p8r3-83r8-jwj5` to overwrite files on the host syste…
- CVE-2023-32080CRITICALCVSS 9.0EG 9.0fixed in 1.7.5 or 1.11.6, by version range2023-05-10
Wings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions 1.11.0 prior to 1.11.6 impacts anyone running the affected versions of Wings. This vulnerability can be used to gain a…
- CVE-2024-27102CRITICALCVSS 9.9EG 9.9fixed in 1.11.92024-03-13
Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used to access files and directories on the host system. The full scope…
- CVE-2024-34066HIGHCVSS 8.4EG 8.4fixed in 1.11.122024-05-03
Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read a…
- CVE-2024-34068MEDIUMCVSS 6.4EG 6.4fixed in 1.11.122024-05-03
Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the previously implemented access control (GHSA-6rg3-8h8x-5xfv) that prevents accessing internal e…
- CVE-2025-68954MEDIUMCVSS 5.4EG 5.4fixed in 1.12.02026-01-06
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access ov…
- CVE-2025-69199MEDIUMCVSS 6.5EG 6.5fixed in 1.12.02026-01-19
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.0, websockets within wings lack proper rate limiting and throttling. As a result a malicious user can open a large n…
- CVE-2026-21696MEDIUMCVSS 6.5EG 6.5fixed in 1.12.02026-01-19
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version 1.7.0 and prior to version 1.12.0, Wings does not consider SQLite max parameter limit when processing activity log ent…
- CVE-2026-52855CRITICALCVSS 9.9EG 9.9fixed in 1.12.32026-07-31
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{conf…
- CVE-2026-52856HIGHCVSS 7.5EG 7.5fixed in 1.13.02026-07-31
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
- CVE-2026-52857MEDIUMCVSS 5.5EG 5.5fixed in 1.13.02026-07-31
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process an oversized non-file parser configurat…
- CVE-2026-54593HIGHCVSS 8.1EG 8.1fixed in 1.12.22026-07-28
Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_…
Check whether github.com/pterodactyl/wings is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/pterodactyl/wings CVEs against the assets you own.
Book a Demo →