go

github.com/pterodactyl/wings

View on go registry
34 Total advisories
34 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/pterodactyl/wings is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 8.4
Go

CVE-2024-34066

Pterodactyl Wings vulnerable to Arbitrary File Write/Read

CRITICAL 9.9
Go

CVE-2024-27102

Pterodactyl Wings vulnerable to improper isolation of server file access

CRITICAL 9.0
Go

CVE-2023-32080

Wings vulnerable to escape to host from installation container

HIGH 8.1
Packagist

CVE-2026-54593

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions

CRITICAL 9.9
Go

CVE-2026-52855

Wings exposes node configuration secrets through egg configuration-file templating

MEDIUM 5.5
Go

CVE-2026-52857

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM

HIGH 7.5
Go

CVE-2026-52856

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service

UNKNOWN
Go

CVE-2026-54593

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings

UNKNOWN
Go

CVE-2026-52855

Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings

UNKNOWN
Go

CVE-2026-52857

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings

UNKNOWN
Go

CVE-2026-52856

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings

MEDIUM 6.5
Go

CVE-2021-32699

Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings

MEDIUM 5.0
Go

GO-2026-5814

Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container

UNKNOWN
Go

GHSA-rhq6-9rgh-v45c

Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings

UNKNOWN
Go

CVE-2025-68954

Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings

UNKNOWN
Go

CVE-2025-69199

Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings

UNKNOWN
Go

CVE-2026-21696

Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings

UNKNOWN
Go

CVE-2024-34066

Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings

UNKNOWN
Go

CVE-2024-34068

Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings

UNKNOWN
Go

CVE-2024-27102

Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings

UNKNOWN
Go

CVE-2023-32080

Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings

UNKNOWN
Go

CVE-2023-25168

Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings

UNKNOWN
Go

GHSA-6rg3-8h8x-5xfv

Unchecked hostname resolution could allow access to local network resources by users outside the local network in github.com/pterodactyl/wings

UNKNOWN
Go

CVE-2023-25152

Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings

UNKNOWN
Go

CVE-2021-32699

Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings

UNKNOWN
Go

GHSA-hr7j-63v7-vj7g

Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings

UNKNOWN
Packagist

GO-2026-4497

Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change

MEDIUM 6.4
Go

CVE-2024-34068

Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull

MEDIUM 6.4
Go

GO-2022-0389

Unchecked hostname resolution could allow access to local network resources by users outside the local network

CRITICAL 9.6
Go

CVE-2023-25168

Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system

HIGH 8.4
Go

CVE-2023-25152

Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following

MEDIUM 6.5
Go

CVE-2025-69199

Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks

MEDIUM 6.5
Go

CVE-2026-21696

Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered

UNKNOWN
Packagist

CVE-2025-68954

Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes