{"schema_version":1,"title":"github.com/pterodactyl/wings (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 21 vulnerabilities in github.com/pterodactyl/wings (Go): 0 in the last 7 days and 5 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-52856, was published on 31 July 2026.","url":"https://junglewise.ai/threats/technologies/github-com-pterodactyl-wings","json_url":"https://junglewise.ai/threats/technologies/github-com-pterodactyl-wings.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-pterodactyl-wings","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":21,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":5,"last_365_days":12},"latest":[{"cve":"CVE-2026-52856","cvss":7.5,"epss":0.0061,"slug":"cve-2026-52856-pterodactyl-wings-denial-of-service-in-sftp-handshake","title":"Pterodactyl Wings denial of service in SFTP handshake","severity":"high","exploited":false,"published_at":"2026-07-31T17:16:33.46+00:00","url":"https://junglewise.ai/threats/cve-2026-52856-pterodactyl-wings-denial-of-service-in-sftp-handshake"},{"cve":"CVE-2026-52855","cvss":9.9,"epss":0.0051,"slug":"cve-2026-52855-pterodactyl-wings-sensitive-information-disclosure-in-egg","title":"Pterodactyl Wings sensitive information disclosure in egg templates","severity":"critical","exploited":false,"published_at":"2026-07-31T17:16:33.313+00:00","url":"https://junglewise.ai/threats/cve-2026-52855-pterodactyl-wings-sensitive-information-disclosure-in-egg"},{"cve":"CVE-2026-52857","cvss":5.5,"epss":0.0016,"slug":"cve-2026-52857-pterodactyl-wings-memory-exhaustion-in-configuration-file-parsers","title":"Pterodactyl Wings memory exhaustion in configuration file parsers","severity":"medium","exploited":false,"published_at":"2026-07-31T16:17:06.49+00:00","url":"https://junglewise.ai/threats/cve-2026-52857-pterodactyl-wings-memory-exhaustion-in-configuration-file-parsers"},{"cve":"CVE-2026-54593","cvss":8.1,"epss":0.0068,"slug":"cve-2026-54593-pterodactyl-panel-and-wings-privilege-escalation-via-jwt-scope","title":"Pterodactyl Panel and Wings privilege escalation via JWT scope reuse","severity":"high","exploited":false,"published_at":"2026-07-28T16:19:00.097+00:00","url":"https://junglewise.ai/threats/cve-2026-54593-pterodactyl-panel-and-wings-privilege-escalation-via-jwt-scope"},{"slug":"go-2026-5814-pterodactyl-wings-chmod-operation-can-be-used-to-change-10b15da7","title":"GO-2026-5814 - Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container in github.com/pterodactyl/wing","severity":"info","exploited":false,"published_at":"2026-07-07T15:26:32+00:00","url":"https://junglewise.ai/threats/go-2026-5814-pterodactyl-wings-chmod-operation-can-be-used-to-change-10b15da7"},{"cvss":5,"slug":"pterodactyl-wings-symlink-follow-in-chmod-operation-f835b178","title":"Pterodactyl Wings symlink follow in chmod operation","severity":"medium","exploited":false,"published_at":"2026-06-26T20:53:00+00:00","url":"https://junglewise.ai/threats/pterodactyl-wings-symlink-follow-in-chmod-operation-f835b178"},{"cvss":3.1,"slug":"pterodactyl-wings-chmod-operation-can-be-used-to-change-permissions-of-eefb7fae","title":"Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container","severity":"low","exploited":false,"published_at":"2026-06-26T20:53:00+00:00","url":"https://junglewise.ai/threats/pterodactyl-wings-chmod-operation-can-be-used-to-change-permissions-of-eefb7fae"},{"slug":"go-2026-4497-pterodactyl-panel-s-sftp-sessions-remain-active-after-user-975e8bd5","title":"GO-2026-4497 - Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change in github.com/pterodactyl/wings","severity":"info","exploited":false,"published_at":"2026-02-23T18:23:12+00:00","url":"https://junglewise.ai/threats/go-2026-4497-pterodactyl-panel-s-sftp-sessions-remain-active-after-user-975e8bd5"},{"cvss":4,"slug":"pterodactyl-panel-s-sftp-sessions-remain-active-after-user-account-fdf64de0","title":"Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change","severity":"medium","exploited":false,"published_at":"2026-02-17T17:15:18+00:00","url":"https://junglewise.ai/threats/pterodactyl-panel-s-sftp-sessions-remain-active-after-user-account-fdf64de0"},{"cve":"CVE-2025-69199","cvss":3.1,"epss":0.0029,"slug":"cve-2025-69199-pterodactyl-websocket-endpoints-have-no-visible-rate-limits-or","title":"GO-2026-4331 - Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks in github.com/pterodactyl/wings","severity":"low","exploited":false,"published_at":"2026-02-03T20:37:17+00:00","url":"https://junglewise.ai/threats/cve-2025-69199-pterodactyl-websocket-endpoints-have-no-visible-rate-limits-or"},{"cve":"CVE-2026-21696","cvss":3.1,"epss":0.0054,"slug":"cve-2026-21696-pterodactyl-endlessly-reprocesses-reuploads-activity-log-data-due","title":"GO-2026-4329 - Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered in github.com/pterodac","severity":"low","exploited":false,"published_at":"2026-02-03T20:37:17+00:00","url":"https://junglewise.ai/threats/cve-2026-21696-pterodactyl-endlessly-reprocesses-reuploads-activity-log-data-due"},{"cve":"CVE-2025-68954","cvss":4,"epss":0.0025,"slug":"cve-2025-68954-pterodactyl-does-not-revoke-sftp-access-when-server-is-deleted-or","title":"GO-2026-4283 - Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings","severity":"medium","exploited":false,"published_at":"2026-01-12T17:39:39+00:00","url":"https://junglewise.ai/threats/cve-2025-68954-pterodactyl-does-not-revoke-sftp-access-when-server-is-deleted-or"},{"cve":"CVE-2021-32699","cvss":3.1,"epss":0.0027,"slug":"cve-2021-32699-asymmetric-resource-consumption-amplification-in-docker","title":"GO-2022-0919 - Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings in github.com/pterodactyl/wings","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:08+00:00","url":"https://junglewise.ai/threats/cve-2021-32699-asymmetric-resource-consumption-amplification-in-docker"},{"slug":"go-2022-0389-unchecked-hostname-resolution-could-allow-access-to-local-9496631a","title":"GO-2022-0389 - Unchecked hostname resolution could allow access to local network resources by users outside the local network in github.com/pterodactyl/win","severity":"info","exploited":false,"published_at":"2024-08-21T14:30:31+00:00","url":"https://junglewise.ai/threats/go-2022-0389-unchecked-hostname-resolution-could-allow-access-to-local-9496631a"},{"cve":"CVE-2023-32080","cvss":3.1,"epss":0.0092,"slug":"cve-2023-32080-wings-vulnerable-to-escape-to-host-from-installation-container","title":"GO-2023-1768 - Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings","severity":"low","exploited":false,"published_at":"2024-08-20T20:29:19+00:00","url":"https://junglewise.ai/threats/cve-2023-32080-wings-vulnerable-to-escape-to-host-from-installation-container"},{"cve":"CVE-2023-25168","cvss":3.1,"epss":0.0096,"slug":"cve-2023-25168-pterodactyl-wings-contains-unix-symbolic-link-symlink-following","title":"GO-2023-1555 - Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in githu","severity":"low","exploited":false,"published_at":"2024-08-20T20:26:01+00:00","url":"https://junglewise.ai/threats/cve-2023-25168-pterodactyl-wings-contains-unix-symbolic-link-symlink-following"},{"cve":"CVE-2023-25152","cvss":3.1,"epss":0.0068,"slug":"cve-2023-25152-pterodactyl-wings-contains-unix-symbolic-link-symlink-following","title":"GO-2023-1542 - Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings","severity":"low","exploited":false,"published_at":"2024-08-20T20:26:01+00:00","url":"https://junglewise.ai/threats/cve-2023-25152-pterodactyl-wings-contains-unix-symbolic-link-symlink-following"},{"cve":"CVE-2024-34068","cvss":3.1,"epss":0.0039,"slug":"cve-2024-34068-pterodactyl-wings-vulnerable-to-server-side-request-forgery","title":"GO-2024-2815 - Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings","severity":"low","exploited":false,"published_at":"2024-06-10T16:39:03+00:00","url":"https://junglewise.ai/threats/cve-2024-34068-pterodactyl-wings-vulnerable-to-server-side-request-forgery"},{"cve":"CVE-2024-34066","cvss":3.1,"epss":0.0054,"slug":"cve-2024-34066-pterodactyl-wings-vulnerable-to-arbitrary-file-write-read","title":"GO-2024-2814 - Pterodactyl Wings vulnerable to Arbitrary File Write/Read in github.com/pterodactyl/wings","severity":"low","exploited":false,"published_at":"2024-06-04T15:19:21+00:00","url":"https://junglewise.ai/threats/cve-2024-34066-pterodactyl-wings-vulnerable-to-arbitrary-file-write-read"},{"cve":"CVE-2024-27102","cvss":3.1,"epss":0.0055,"slug":"cve-2024-27102-pterodactyl-wings-vulnerable-to-improper-isolation-of-server-file","title":"GO-2024-2642 - Pterodactyl Wings vulnerable to improper isolation of server file access in github.com/pterodactyl/wings","severity":"low","exploited":false,"published_at":"2024-06-04T15:19:21+00:00","url":"https://junglewise.ai/threats/cve-2024-27102-pterodactyl-wings-vulnerable-to-improper-isolation-of-server-file"},{"cvss":3.1,"slug":"unchecked-hostname-resolution-could-allow-access-to-local-network-b022a740","title":"Unchecked hostname resolution could allow access to local network resources by users outside the local network","severity":"low","exploited":false,"published_at":"2021-06-23T18:04:50+00:00","url":"https://junglewise.ai/threats/unchecked-hostname-resolution-could-allow-access-to-local-network-b022a740"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":1,"exploited":0,"vulnerabilities":4},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"}],"technology":{"hub":true,"name":"github.com/pterodactyl/wings (Go)","slug":"github-com-pterodactyl-wings","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://pterodactyl.io/","repo_url":"https://github.com/pterodactyl/wings","description":"The server-side control plane for the Pterodactyl game server management panel.","url":"https://junglewise.ai/threats/technologies/github-com-pterodactyl-wings"},"most_severe":[{"cve":"CVE-2026-52855","cvss":9.9,"epss":0.0051,"slug":"cve-2026-52855-pterodactyl-wings-sensitive-information-disclosure-in-egg","title":"Pterodactyl Wings sensitive information disclosure in egg templates","severity":"critical","exploited":false,"published_at":"2026-07-31T17:16:33.313+00:00","url":"https://junglewise.ai/threats/cve-2026-52855-pterodactyl-wings-sensitive-information-disclosure-in-egg"},{"cve":"CVE-2026-54593","cvss":8.1,"epss":0.0068,"slug":"cve-2026-54593-pterodactyl-panel-and-wings-privilege-escalation-via-jwt-scope","title":"Pterodactyl Panel and Wings privilege escalation via JWT scope reuse","severity":"high","exploited":false,"published_at":"2026-07-28T16:19:00.097+00:00","url":"https://junglewise.ai/threats/cve-2026-54593-pterodactyl-panel-and-wings-privilege-escalation-via-jwt-scope"},{"cve":"CVE-2026-52856","cvss":7.5,"epss":0.0061,"slug":"cve-2026-52856-pterodactyl-wings-denial-of-service-in-sftp-handshake","title":"Pterodactyl Wings denial of service in SFTP handshake","severity":"high","exploited":false,"published_at":"2026-07-31T17:16:33.46+00:00","url":"https://junglewise.ai/threats/cve-2026-52856-pterodactyl-wings-denial-of-service-in-sftp-handshake"},{"cve":"CVE-2026-52857","cvss":5.5,"epss":0.0016,"slug":"cve-2026-52857-pterodactyl-wings-memory-exhaustion-in-configuration-file-parsers","title":"Pterodactyl Wings memory exhaustion in configuration file parsers","severity":"medium","exploited":false,"published_at":"2026-07-31T16:17:06.49+00:00","url":"https://junglewise.ai/threats/cve-2026-52857-pterodactyl-wings-memory-exhaustion-in-configuration-file-parsers"},{"cvss":5,"slug":"pterodactyl-wings-symlink-follow-in-chmod-operation-f835b178","title":"Pterodactyl Wings symlink follow in chmod operation","severity":"medium","exploited":false,"published_at":"2026-06-26T20:53:00+00:00","url":"https://junglewise.ai/threats/pterodactyl-wings-symlink-follow-in-chmod-operation-f835b178"},{"cve":"CVE-2025-68954","cvss":4,"epss":0.0025,"slug":"cve-2025-68954-pterodactyl-does-not-revoke-sftp-access-when-server-is-deleted-or","title":"GO-2026-4283 - Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings","severity":"medium","exploited":false,"published_at":"2026-01-12T17:39:39+00:00","url":"https://junglewise.ai/threats/cve-2025-68954-pterodactyl-does-not-revoke-sftp-access-when-server-is-deleted-or"},{"cvss":4,"slug":"pterodactyl-panel-s-sftp-sessions-remain-active-after-user-account-fdf64de0","title":"Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change","severity":"medium","exploited":false,"published_at":"2026-02-17T17:15:18+00:00","url":"https://junglewise.ai/threats/pterodactyl-panel-s-sftp-sessions-remain-active-after-user-account-fdf64de0"},{"cve":"CVE-2023-25168","cvss":3.1,"epss":0.0096,"slug":"cve-2023-25168-pterodactyl-wings-contains-unix-symbolic-link-symlink-following","title":"GO-2023-1555 - Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system in githu","severity":"low","exploited":false,"published_at":"2024-08-20T20:26:01+00:00","url":"https://junglewise.ai/threats/cve-2023-25168-pterodactyl-wings-contains-unix-symbolic-link-symlink-following"},{"cve":"CVE-2023-32080","cvss":3.1,"epss":0.0092,"slug":"cve-2023-32080-wings-vulnerable-to-escape-to-host-from-installation-container","title":"GO-2023-1768 - Wings vulnerable to escape to host from installation container in github.com/pterodactyl/wings","severity":"low","exploited":false,"published_at":"2024-08-20T20:29:19+00:00","url":"https://junglewise.ai/threats/cve-2023-32080-wings-vulnerable-to-escape-to-host-from-installation-container"},{"cve":"CVE-2023-25152","cvss":3.1,"epss":0.0068,"slug":"cve-2023-25152-pterodactyl-wings-contains-unix-symbolic-link-symlink-following","title":"GO-2023-1542 - Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings","severity":"low","exploited":false,"published_at":"2024-08-20T20:26:01+00:00","url":"https://junglewise.ai/threats/cve-2023-25152-pterodactyl-wings-contains-unix-symbolic-link-symlink-following"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}