Denial of Service Vulnerability in Pterodactyl's Wings by Pterodactyl
CVE-2025-69199

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
19 January 2026

What is CVE-2025-69199?

Wings, the control plane for Pterodactyl, has a vulnerability in its websocket implementation prior to version 1.12.0 due to a lack of proper rate limiting and throttling mechanisms. This allows a malicious actor to open numerous websocket connections simultaneously, leading to excessive data requests that can overwhelm the host system's CPU and memory resources. Furthermore, there is no cap on the total size of messages that can be transmitted, which can trigger significant performance degradation as the server struggles to manage thousands of connections and massive data volumes. The issue has been addressed in version 1.12.0.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

panel < 1.12.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.