CVE-2021-32699Medium· 6.5▾ SunlitAsymmetric Resource Consumption (Amplification) in Docker containers created by Wings
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
All versions of Pterodactyl Wings preior to 1.4.4 are vulnerable to system resource exhaustion due to improper container process limits being defined. A malicious user can consume more resources than intended and cause downstream impacts to other clients on the same hardware, eventually causing the physical server to stop responding.
Users should upgrade to 1.4.4.
There is no non-code based workaround for impacted versions of the software. Users running customized versions of this software can manually set a PID limit for containers created.
If you have any questions or comments about this advisory:
dane ät pterodactyl dot iogithub.com/pterodactyl/wings < 1.4.4Upgrade to a patched release:
github.com/pterodactyl/wings 1.4.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-52857Medium· 5.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel
CVE-2026-52855Critical· 9.9Wings is the server control plane for Pterodactyl, a free, open-source game server management panel
CVE-2026-52856High· 7.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel
GHSA-rhq6-9rgh-v45cMedium· 5.0Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container
CVE-2024-27102Critical· 9.9Wings is the server control plane for Pterodactyl Panel
CVE-2026-86177High· 8.8Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands