Denial of Service Vulnerability in Pterodactyl's Wings by Pterodactyl
CVE-2025-69199
8.3HIGH
What is CVE-2025-69199?
Wings, the control plane for Pterodactyl, has a vulnerability in its websocket implementation prior to version 1.12.0 due to a lack of proper rate limiting and throttling mechanisms. This allows a malicious actor to open numerous websocket connections simultaneously, leading to excessive data requests that can overwhelm the host system's CPU and memory resources. Furthermore, there is no cap on the total size of messages that can be transmitted, which can trigger significant performance degradation as the server struggles to manage thousands of connections and massive data volumes. The issue has been addressed in version 1.12.0.
Affected Version(s)
panel < 1.12.0
