GHSA-q6hh-gp44-4hcmMediumCVSS 5.5

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM

Published
July 31, 2026
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

Config file parsers, json, yaml, xml etc in parser.go have no file size limit/checks, allowing for a giant config file to potentially OOM the wings process.

Impact

All wings users who have an egg with a non-file parser configuration file setting.

🎯 Affected products1

  • go/github.com/pterodactyl/wings:< 1.13.0

🔗 References (4)