GHSA-q6hh-gp44-4hcmMediumCVSS 5.5
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
🔗 CVE IDs covered (1)
📋 Description
Summary
Config file parsers, json, yaml, xml etc in parser.go have no file size limit/checks, allowing for a giant config file to potentially OOM the wings process.
Impact
All wings users who have an egg with a non-file parser configuration file setting.
🎯 Affected products1
- go/github.com/pterodactyl/wings:< 1.13.0