VendorsPterodactylwingsall versions
Vulnerabilities

Pterodactyl Wings

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2024-27102
Improper isolation of server file access in github.com/pterodactyl/wings
Published 2024-03-13 · Analyzed
9.9EPSS 0.006
CVE-2023-25168
Symbolic Link (Symlink) Following allowing the deletion of files and directories on the host system in wings
Published 2023-02-08 · Modified
9.6EPSS 0.010
CVE-2023-32080
Wings vulnerable to escape to host from installation container
Published 2023-05-10 · Modified
9.0EPSS 0.009
CVE-2023-25152
Symbolic Link (Symlink) Following in github.com/pterodactyl/wings
Published 2023-02-08 · Modified
8.8EPSS 0.007
CVE-2024-34066
Arbitrary File Write/Read in Pterodactyl wings
Published 2024-05-03 · Analyzed
8.4EPSS 0.005
CVE-2026-21696
Endless reprocessing/reupload of activity log data due to SQLite max parameters limit not being considered
Published 2026-01-19 · Analyzed
8.3EPSS 0.005
CVE-2025-69199
Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstances
Published 2026-01-19 · Analyzed
8.3EPSS 0.003
CVE-2025-68954
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
Published 2026-01-06 · Analyzed
7.5EPSS 0.002
CVE-2021-32699
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
Published 2021-06-22 · Modified
6.5EPSS 0.003
CVE-2024-34068
Server-side Request Forgery during remote file pull in Pterodactyl wings
Published 2024-05-03 · Analyzed
6.4EPSS 0.004