All 8 CVE vulnerabilities found in wings, with AI-generated Chinese analysis, references, and POCs.
Vendor: pterodactyl
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2026-21696 | Endless reprocessing/reupload of activity log data due to SQLite max parameters limit not being considered CWE-400 | 7.1AI | HighAI | 2026-01-19 |
| CVE-2024-34066 | Arbitrary File Write/Read in Pterodactyl wings CWE-552 | 8.5 | High | 2024-05-03 |
| CVE-2024-34068 | Server-side Request Forgery during remote file pull in Pterodactyl wings CWE-284 | 6.4 | Medium | 2024-05-03 |
| CVE-2024-27102 | Improper isolation of server file access in github.com/pterodactyl/wings CWE-22 | 10.0 | Critical | 2024-03-13 |
| CVE-2023-32080 | Wings vulnerable to escape to host from installation container CWE-250 | 9.1 | Critical | 2023-05-10 |
| CVE-2023-25168 | Symbolic Link (Symlink) Following allowing the deletion of files and directories on the host system in wings CWE-59 | 9.6 | Critical | 2023-02-08 |
| CVE-2023-25152 | Symbolic Link (Symlink) Following in github.com/pterodactyl/wings CWE-59 | 8.4 | High | 2023-02-08 |
| CVE-2021-32699 | Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings CWE-400 | 6.5 | Medium | 2021-06-22 |
All 8 known CVE vulnerabilities affecting wings with full Chinese analysis, references, and POCs where available.