github.com/pterodactyl/wings
The server control plane for Pterodactyl Panel. Written from the ground-up with security, speed, and stability in mind.
Activity
- Latest release
- 1mo ago
- Total releases
- 63
- Cadence
- ~16 days
- Last 12 months
- 8
Reach
- Stars
- 1.0k
Details
- First release
- Dec 23, 2019
| Version | Released | |
|---|---|---|
v1.13.3
patch
|
v1.13.3
patch
Dependencies (44)
+ 36 more |
|
v1.13.2
patch
|
v1.13.2
patch
Dependencies (44)
+ 36 more |
|
v1.13.1
patch
|
v1.13.1
patch
Dependencies (44)
+ 36 more |
|
v1.13.0
minor
|
v1.13.0
minor
Dependencies (44)
+ 36 more |
|
v1.12.3
patch
2 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev |
v1.12.3
patch
Dependencies (44)
+ 36 more |
|
v1.12.2
minor
3 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev |
v1.12.2
minor
Dependencies (44)
+ 36 more |
|
v1.12.1
patch
5 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-5814
GHSA-rhq6-9rgh-v45c
Jul 07, 2026
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Fixed in
1.12.2
Updated Jul 07, 2026 · Source: OSV.dev |
v1.12.1
patch
Dependencies (44)
+ 36 more |
|
v1.12.0
minor
6 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-5814
GHSA-rhq6-9rgh-v45c
Jul 07, 2026
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Fixed in
1.12.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev |
v1.12.0
minor
Dependencies (44)
+ 36 more |
|
v1.11.13
patch
9 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-5814
GHSA-rhq6-9rgh-v45c
Jul 07, 2026
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Fixed in
1.12.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.13
patch
Dependencies (45)
+ 37 more |
|
v1.11.12
patch
9 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-5814
GHSA-rhq6-9rgh-v45c
Jul 07, 2026
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Fixed in
1.12.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.12
patch
Dependencies (45)
+ 37 more |
|
v1.11.11
patch
11 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-5814
GHSA-rhq6-9rgh-v45c
Jul 07, 2026
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Fixed in
1.12.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.11
patch
Dependencies (45)
+ 37 more |
|
v1.11.10
patch
11 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-5814
GHSA-rhq6-9rgh-v45c
Jul 07, 2026
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Fixed in
1.12.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.10
patch
Dependencies (45)
+ 37 more |
|
v1.11.9
patch
11 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-5814
GHSA-rhq6-9rgh-v45c
Jul 07, 2026
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings Fixed in
1.12.2
Updated Jul 07, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.9
patch
Dependencies (45)
+ 37 more |
|
v1.11.8
patch
11 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.8
patch
Dependencies (45)
+ 37 more |
|
v1.11.7
patch
11 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.7
patch
Dependencies (45)
+ 37 more |
|
v1.11.6
patch
11 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.6
patch
Dependencies (45)
+ 37 more |
|
v1.7.5
patch
11 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.7.5
patch
Dependencies (45)
+ 37 more |
|
v1.11.5
patch
12 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.5
patch
Dependencies (45)
+ 37 more |
|
v1.7.4
patch
12 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.7.4
patch
Dependencies (45)
+ 37 more |
|
v1.11.4
patch
12 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.4
patch
Dependencies (45)
+ 37 more |
|
v1.11.3
patch
13 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.3
patch
Dependencies (45)
+ 37 more |
|
v1.7.3
patch
13 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.7.3
patch
Dependencies (45)
+ 37 more |
|
v1.11.2
patch
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.2
patch
Dependencies (45)
+ 37 more |
|
v1.11.1
patch
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.1
patch
Dependencies (45)
+ 37 more |
|
v1.11.0
minor
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.0
minor
Dependencies (45)
+ 37 more |
|
v1.11.0-rc.2
pre
11 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.0-rc.2
pre
Dependencies (45)
+ 37 more |
|
v1.11.0-rc.1
pre
11 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.0-rc.1
pre
Dependencies (45)
+ 37 more |
|
v1.7.2
patch
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.7.2
patch
Dependencies (45)
+ 37 more |
|
v1.7.1
minor
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-21696
GO-2026-4329
GHSA-2497-gp99-2m74
Feb 03, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings Fixed in
1.12.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.7.1
minor
Dependencies (45)
+ 37 more |
|
v1.6.3
patch
13 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.6.3
patch
Dependencies (40)
+ 32 more |
|
v1.6.2
patch
13 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.6.2
patch
Dependencies (40)
+ 32 more |
|
v1.6.1
minor
13 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.6.1
minor
Dependencies (41)
+ 33 more |
|
v1.5.4
patch
13 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.4
patch
Dependencies (40)
+ 32 more |
|
v1.5.3
patch
13 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.3
patch
Dependencies (40)
+ 32 more |
|
v1.5.2
patch
13 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.2
patch
Dependencies (40)
+ 32 more |
|
v1.5.0
minor
13 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.0
minor
Dependencies (41)
+ 33 more |
|
v1.4.7
patch
13 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.7
patch
Dependencies (41)
+ 33 more |
|
v1.4.6
patch
13 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.6
patch
Dependencies (41)
+ 33 more |
|
v1.4.4
patch
13 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.4
patch
Dependencies (41)
+ 33 more |
|
v1.4.1
patch
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32699
GO-2022-0919
GHSA-jj6m-r8jc-2gp7
Aug 21, 2024
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (40)
+ 32 more |
|
v1.4.0
minor
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32699
GO-2022-0919
GHSA-jj6m-r8jc-2gp7
Aug 21, 2024
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (40)
+ 32 more |
|
v1.3.2
patch
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32699
GO-2022-0919
GHSA-jj6m-r8jc-2gp7
Aug 21, 2024
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.2
patch
Dependencies (40)
+ 32 more |
|
v1.3.1
minor
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32699
GO-2022-0919
GHSA-jj6m-r8jc-2gp7
Aug 21, 2024
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.3.1
minor
Dependencies (40)
+ 32 more |
|
v1.2.2
patch
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32699
GO-2022-0919
GHSA-jj6m-r8jc-2gp7
Aug 21, 2024
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.2
patch
Dependencies (39)
+ 31 more |
|
v1.2.1
patch
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32699
GO-2022-0919
GHSA-jj6m-r8jc-2gp7
Aug 21, 2024
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (39)
+ 31 more |
|
v1.2.0
minor
15 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32699
GO-2022-0919
GHSA-jj6m-r8jc-2gp7
Aug 21, 2024
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0389
GHSA-6rg3-8h8x-5xfv
Aug 21, 2024
Unchecked hostname resolution could allow access to local network resources by users outside the local network in github.com/pterodactyl/wings Unchecked hostname resolution could allow access to local network resources by users outside the local network in github.com/pterodactyl/wings Fixed in
1.2.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (39)
+ 31 more |
|
v1.1.3
patch
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32699
GO-2022-0919
GHSA-jj6m-r8jc-2gp7
Aug 21, 2024
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.3
patch
Dependencies (39)
+ 31 more |
|
v1.1.2
patch
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32699
GO-2022-0919
GHSA-jj6m-r8jc-2gp7
Aug 21, 2024
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.2
patch
Dependencies (40)
+ 32 more |
|
v1.1.0
minor
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32699
GO-2022-0919
GHSA-jj6m-r8jc-2gp7
Aug 21, 2024
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (40)
+ 32 more |
|
v1.0.1
initial
14 CVEs
CVE-2026-52856
GO-2026-6156
GHSA-ghrq-5wpp-hxx5
Aug 18, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-54593
GO-2026-6120
GHSA-8r6w-3qq5-4p4r
Aug 18, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted Fixed in
1.12.2
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52857
GO-2026-6159
GHSA-q6hh-gp44-4hcm
Aug 18, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings Fixed in
1.13.0
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-52855
GO-2026-6158
GHSA-pfvc-3p5h-x7h6
Aug 18, 2026
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings Fixed in
1.12.3
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-4497
GHSA-hr7j-63v7-vj7g
Feb 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings Fixed in
1.12.1
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2025-69199
GO-2026-4331
GHSA-8w7m-w749-rx98
Feb 03, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-68954
GO-2026-4283
GHSA-8c39-xppg-479c
Jan 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings Fixed in
1.12.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32699
GO-2022-0919
GHSA-jj6m-r8jc-2gp7
Aug 21, 2024
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings Fixed in
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-32080
GO-2023-1768
GHSA-p744-4q6p-hvc2
Aug 20, 2024
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings Fixed in
1.7.5
1.11.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25168
GO-2023-1555
GHSA-66p8-j459-rq63
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings Fixed in
1.7.4
1.11.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-25152
GO-2023-1542
GHSA-p8r3-83r8-jwj5
Aug 20, 2024
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings Fixed in
1.7.3
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34068
GO-2024-2815
GHSA-qq22-jj8x-4wwv
Jun 10, 2024
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-34066
GO-2024-2814
GHSA-gqmf-jqgv-v8fw
Jun 04, 2024
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings Fixed in
1.11.12
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-27102
GO-2024-2642
GHSA-494h-9924-xww9
Jun 04, 2024
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings Fixed in
1.11.9
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.1
initial
Dependencies (40)
+ 32 more |