Security: pterodactyl/wings
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Prefix-based Docker registry matching leaks credentials to attacker-controlled registriesGHSA-4g8v-75pm-x7f6 published
Aug 14, 2026 by robertdrakedennisHigh -
Integer overflow in upload and archive quota calculations allows disk-quota bypassGHSA-5mgr-9frx-2rh7 published
Aug 14, 2026 by robertdrakedennisHigh -
Backup restore URLs permit SSRF against loopback, private, link-local, and redirect destinationsGHSA-7w9q-4q32-wfj8 published
Aug 14, 2026 by robertdrakedennisHigh -
Unsanitized backup identifiers permit host filesystem path traversalGHSA-77pg-7gfq-9hjr published
Aug 14, 2026 by robertdrakedennisCritical -
SFTP streaming writes bypass per-server disk quotas, allowing node-wide denial of serviceGHSA-hfvm-879c-xgmm published
Aug 14, 2026 by robertdrakedennisHigh -
SFTP write path enforces disk quota only as a stale pre-flight check, allowing tenants to fill the host disk without bound (DoS)GHSA-8j54-xcwx-597p published
Aug 14, 2026 by robertdrakedennisHigh -
Maliciously or erroneously created parsed config files can cause wings process to OOMGHSA-q6hh-gp44-4hcm published
Jun 15, 2026 by WilliamVennerModerate -
Maliciously crafted packet during SFTP connection handshake causes denial of serviceGHSA-ghrq-5wpp-hxx5 published
Jun 15, 2026 by WilliamVennerHigh -
Wings exposes node configuration secrets through egg configuration-file templatingGHSA-pfvc-3p5h-x7h6 published
Jun 12, 2026 by anthonyphysgunCritical -
Chmod operation can be used to change permissions of files outside of the server containerGHSA-rhq6-9rgh-v45c published
May 23, 2026 by DaneEverittModerate
Learn more about advisories related to pterodactyl/wings in the GitHub Advisory Database