Vulnerabilities in pterodactyl
28 resultsVexday analysis
O Pterodactyl apresenta 20 vulnerabilidades catalogadas, das quais 5 são críticas, mas nenhuma está sob ataque ativo no momento. A fraqueza dominante (CWE-400 - Controle Inadequado de Recursos) sugere problemas de negação de serviço, com apenas 1 vulnerabilidade publicada nos últimos 90 dias, indicando que o risco é mais histórico que emergente.
CVE-2025-69197MEDIUMPterodactyl TOTPs can be reused during validity windowEPSS 0.4%CVE-2026-35202LOWPterodactyl has a database resource limit bypass via race condition in Client APIEPSS 0.3%CVE-2025-69199HIGHPterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstancesEPSS 0.3%CVE-2021-32699MEDIUMAsymmetric Resource Consumption (Amplification) in Docker containers created by WingsEPSS 0.3%CVE-2025-68954HIGHPterodactyl does not revoke SFTP access when server is deleted or permissions reducedEPSS 0.2%CVE-2025-69198MEDIUMPterodactyl's improper resource locking allows raced queries to create more resources than allotedEPSS 0.2%CVE-2026-52857MEDIUMWings: Maliciously or erroneously created parsed config files can cause wings process to OOMEPSS 0.2%CVE-2024-49762MEDIUMPterodactyl Panel has plain-text logging of user passwords when two-factor authentication is disabledEPSS 0.1%