VDB

CVE-2025-69199

CVE-2025-69199 PUBLISHED CVSS 8.300000190734863 HIGH

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.0, websockets within wings lack proper rate limiting and throttling. As a result a malicious user can open a large number of connections and then request data through these sockets, causing an excessive volume of data over the network and overloading the host system memory and cpu. Additionally, there is not a limit applied to the total size of messages being sent or received, allowing a malicious user to open thousands of websocket connections and then send massive volumes of information over the socket, overloading the host network, and causing increased CPU and memory load within Wings. Version 1.12.0 patches the issue.

EPSS 0.08% · 23.8th percentile

Risk Scores

CVSS v4.0
8.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
EPSS Score
0.08%
23.8th percentile

Affected Products

VendorProductVersions
pterodactylwings0, 0
github.compterodactyl/wings0, 0
pterodactylpanel*, < 1.12.0

Timeline

  • Jan 19, 2026 CVE Published
  • Jan 20, 2026 EPSS Score
  • Jan 23, 2026 EPSS Score
  • Jan 25, 2026 EPSS Score
  • Jan 28, 2026 EPSS Score
  • Jan 31, 2026 EPSS Score
  • Jan 31, 2026 Security Advisory
  • Feb 2, 2026 CVE Updated
  • Feb 3, 2026 EPSS Score
  • Feb 5, 2026 EPSS Score
  • Feb 8, 2026 EPSS Score
  • Feb 11, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›