GHSA-8w7m-w749-rx98 · Severity: high · Ecosystem: go — Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.0, websockets within wings lack proper rate limiting and throttling. As a result a malicious user can open a large number of connections and then request data through these sockets, causing an excessive volume of data over the network and overloading the host system memory and cpu. Additionally, there is not a limit applied to the total size of messages being sent or received, allowing a malicious user to open thousands of websocket connections and then send massive volumes of information over the socket, overloading the host network, and causing increased CPU and memory load within Wings. Version 1.12.0 patches the issue.
Conclusion & alert: CVE-2025-69199 is rated Low Risk (39.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.05%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-02-20 | 0.04% | 0.05% | +0.01% |
| 2 | 2026-01-20 | — | 0.04% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.3 | 4.0 | HIGH |
|
— | — | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
GHSA-8w7m-w749-rx98 · Severity: high · Ecosystem: go — Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| pterodactyl | wings | < 1.12.0 | cpe:2.3:a:pterodactyl:wings:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/pterodactyl/panel/security/advisories/GHSA-8w7m-w749-rx98 | Vendor Advisory |