CVE-2025-69199 - CVE House
Back to Database
Status published High CVE-2025-69199

Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstances

Vulnerability Description

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.0, websockets within wings lack proper rate limiting and throttling. As a result a malicious user can open a large number of connections and then request data through these sockets, causing an excessive volume of data over the network and overloading the host system memory and cpu. Additionally, there is not a limit applied to the total size of messages being sent or received, allowing a malicious user to open thousands of websocket connections and then send massive volumes of information over the socket, overloading the host network, and causing increased CPU and memory load within Wings. Version 1.12.0 patches the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-69199

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

pterodactyl

View all reports →

Affected Software

panel
Vulnerable Versions:
< 1.12.0

Timeline

Official Publish: January 19th, 2026
Last Modified: January 20th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)