PT-2026-3486 · Pterodactyl · Wings

Published

2026-01-19

·

Updated

2026-02-06

·

CVE-2025-69199

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions Wings versions prior to 1.12.0
Description Wings, the server control plane for Pterodactyl, is affected by an issue where websockets lack appropriate rate limiting and throttling. This allows a malicious user to establish numerous connections and request data, potentially overwhelming the host system's memory and CPU. Furthermore, there is no limit on the size of messages sent or received, enabling an attacker to open thousands of websocket connections and transmit large amounts of data, leading to network overload and increased CPU and memory usage within Wings.
Recommendations Update to version 1.12.0 or later.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-69199
GHSA-8W7M-W749-RX98
GO-2026-4331
SUSE-SU-2026:0403-1

Affected Products

Wings