CVE-2026-52856
published 2026-07-31CVE-2026-52856: Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.34%
26.5th percentile
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | pterodactyl_wings | >= 0 < 1.13.0 | 1.13.0 |
| pterodactyl | wings | < 1.13.0 | 1.13.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
ghsa·2026-07-31
CVE-2026-52856 [HIGH] CWE-129 Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
### Summary
A maliciously crafted packet received & parsed during the SFTP connection handshake will cause a Go panic.
### Impact
All wings users with an open SFTP port.
### Workarounds
Close SFTP port.
VulDB
Pterodactyl Wings up to 1.12.x SFTP input validation
vuldb·2026-07-31·CVSS 7.5
CVE-2026-52856 [HIGH] Pterodactyl Wings up to 1.12.x SFTP input validation
A vulnerability was found in Pterodactyl Wings up to 1.12.x. It has been classified as problematic. This issue affects some unknown processing of the component SFTP. The manipulation leads to improper input validation.
This vulnerability is listed as CVE-2026-52856. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-31
Published