๐Ÿ” CVE Alert

CVE-2026-61617

HIGH 7.7

Pterodactyl Wings SFTP write path does not enforce disk quota, allowing node-wide disk exhaustion

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the host node's physical disk and take down every server on it. Wings checks available space only once, as a boolean, when the write handle is opened, using a stale cached usage value and without knowing the size of the incoming data, and it then returns a raw, unaccounted file handle that is never re-checked as the transfer proceeds. A single upload can therefore be written without bound, far beyond the configured disk limit, until the node's disk is full, and because a server stopped for exceeding its limit is not treated as suspended, SFTP writes are still accepted even after the quota is already exceeded. This issue is fixed in version 1.13.3.

CWE CWE-770 CWE-400
Vendor pterodactyl
Product wings
Published Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for pterodactyl wings

Be the first to know when new high vulnerabilities affecting pterodactyl wings are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

pterodactyl / wings
< 1.13.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pterodactyl/wings/security/advisories/GHSA-8j54-xcwx-597p github.com: https://github.com/pterodactyl/wings/commit/da1a216cfff5867fa66be32cb1edb93e37fd71ff