CVEs we hold for Pterodactyl
Records whose assigning authority named Pterodactyl as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-86177Pterodactyl Panel before 1.14.1 Privilege Escalation via Schedule Taskspterodactyl panel
CVE-2026-61617Pterodactyl Wings SFTP write path does not enforce disk quota, allowing node-wide disk exhaustionpterodactyl wings
CVE-2026-61609Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide…pterodactyl panel
CVE-2026-54593Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissionspterodactyl panel
CVE-2026-52857Wings: Maliciously or erroneously created parsed config files can cause wings process to OOMpterodactyl wings
CVE-2026-52856Wings: Maliciously crafted packet during SFTP connection handshake causes denial of servicepterodactyl wings
CVE-2026-52855Wings exposes node configuration secrets through egg configuration-file templatingpterodactyl wings
CVE-2026-35202Pterodactyl has a database resource limit bypass via race condition in Client APIpterodactyl panel
CVE-2026-26016Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorizationpterodactyl panel
CVE-2026-21696Endless reprocessing/reupload of activity log data due to SQLite max parameters limit not being consideredpterodactyl wings
CVE-2025-69199Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under…pterodactyl panel
CVE-2025-69198Pterodactyl's improper resource locking allows raced queries to create more resources than allotedpterodactyl panel
CVE-2025-68954Pterodactyl does not revoke SFTP access when server is deleted or permissions reducedpterodactyl panel
CVE-2025-49132Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Executionpterodactyl panel
CVE-2024-49762Pterodactyl Panel has plain-text logging of user passwords when two-factor authentication is disabledpterodactyl panel
CVE-2024-34068Server-side Request Forgery during remote file pull in Pterodactyl wingspterodactyl wings
CVE-2024-34067Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panelpterodactyl panel
CVE-2024-27102Improper isolation of server file access in github.com/pterodactyl/wingspterodactyl wings
CVE-2023-25168Symbolic Link (Symlink) Following allowing the deletion of files and directories on the host system in wingspterodactyl wings
CVE-2021-41273Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keyspterodactyl panel
CVE-2021-32699Asymmetric Resource Consumption (Amplification) in Docker containers created by Wingspterodactyl wings
28 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.