7.5
CVE-2026-52856
- EPSS 0.34%
- Veröffentlicht 31.07.2026 16:20:31
- Zuletzt bearbeitet 31.07.2026 19:17:09
- CVE-Watchlists
- Unerledigt
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerpterodactyl
≫
Produkt
wings
Version
< 1.13.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.261 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-129 Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
CWE-248 Uncaught Exception
An exception is thrown from a function, but it is not caught.
CWE-617 Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
CWE-755 Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.
https://github.com/pterodactyl/wings/releases/tag/v1.13.0
https://github.com/pterodactyl/wings/security/advisories/GHSA-ghrq-5wpp-hxx5
https://github.com/pterodactyl/wings/commit/8e49c7c0eda815d3ada171831876a1c14c493026