Untriaged
Permalink
CVE-2026-52857
5.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): High (H)
Activity log
- Created suggestion
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process an oversized non-file parser configuration file and exhaust Wings process memory. This issue is fixed in version 1.13.0.
References
-
https://github.com/pterodactyl/wings/security/advisories/GHSA-q6hh-gp44-4hcm x_refsource_CONFIRM
-
https://github.com/pterodactyl/wings/releases/tag/v1.13.0 x_refsource_MISC
Affected products
wings
- ==< 1.13.0
Matching in nixpkgs
pkgs.wings
Subdivision modeler inspired by Nendo and Mirai from Izware
pkgs.swingsane
Java GUI for SANE scanner servers (saned)
pkgs.python313Packages.pycarwings2
Python library for interacting with the NissanConnect EV
Package maintainers
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>