Dependency scanning
Check whether github.com/pterodactyl/wings is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-34066
Pterodactyl Wings vulnerable to Arbitrary File Write/Read
CVE-2024-27102
Pterodactyl Wings vulnerable to improper isolation of server file access
CVE-2023-32080
Wings vulnerable to escape to host from installation container
CVE-2026-54593
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
CVE-2026-52855
Wings exposes node configuration secrets through egg configuration-file templating
CVE-2026-52857
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
CVE-2026-52856
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
CVE-2026-54593
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings
CVE-2026-52855
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings
CVE-2026-52857
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings
CVE-2026-52856
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings
CVE-2021-32699
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
GO-2026-5814
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container
GHSA-rhq6-9rgh-v45c
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wings
CVE-2025-68954
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings
CVE-2025-69199
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings
CVE-2026-21696
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodactyl/wings
CVE-2024-34066
Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings
CVE-2024-34068
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings
CVE-2024-27102
Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings
CVE-2023-32080
Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings
CVE-2023-25168
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in github.com/pterodactyl/wings
GHSA-6rg3-8h8x-5xfv
Unchecked hostname resolution could allow access to local network resources by users outside the local network in github.com/pterodactyl/wings
CVE-2023-25152
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings
CVE-2021-32699
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings
GHSA-hr7j-63v7-vj7g
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings
GO-2026-4497
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change
CVE-2024-34068
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull
GO-2022-0389
Unchecked hostname resolution could allow access to local network resources by users outside the local network
CVE-2023-25168
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system
CVE-2023-25152
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following
CVE-2025-69199
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks
CVE-2026-21696
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered
CVE-2025-68954
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes