Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-61617— Pterodactyl Wings SFTP write path does not enforce disk quota, allowing node-wide disk exhaustion

Quick assessment

Affected
pterodactyl wings
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Wings 是 Pterodactyl 游戏服务器管理面板的服务端控制平面。在 1.13.2 及更早的版本中,SFTP 写入路径在执行传输过程中并未强制执行服务器的磁盘配额,这使得拥有单个服务器 SFTP 写权限的租户能够耗尽宿主节点的物理磁盘空间,从而导致该节点上的所有服务器宕机。Wings 仅在打开写入句柄时检查一次可用空间(以布尔值形式),使用的是过时的缓存使用量,且未感知待传输数据的大小;随后它返回一个原始的、未计入配额的“裸”文件句柄,并在传输过程中不再进行二次检查。因此,单次上传可以不受限制地写入,远远

CVSS 7.7 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61617

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Pterodactyl Wings SFTP write path does not enforce disk quota, allowing node-wide disk exhaustion
Source: CVE Program / CVE List V5
Vulnerability Description
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the host node's physical disk and take down every server on it. Wings checks available space only once, as a boolean, when the write handle is opened, using a stale cached usage value and without knowing the size of the incoming data, and it then returns a raw, unaccounted file handle that is never re-checked as the transfer proceeds. A single upload can therefore be written without bound, far beyond the configured disk limit, until the node's disk is full, and because a server stopped for exceeding its limit is not treated as suspended, SFTP writes are still accepted even after the quota is already exceeded. This issue is fixed in version 1.13.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
pterodactyl wings < 1.13.3 -

II. Public POCs for CVE-2026-61617

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61617

登录查看更多情报信息。

Patches & Fixes for CVE-2026-61617 (1)

Vendor Advisories for CVE-2026-61617 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-61617

No comments yet


Leave a comment