{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/wings/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-52856"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["wings"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","pterodactyl","go","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Pterodactyl"],"content_html":"\u003cp\u003ePterodactyl Wings, a service used for managing game server instances, is vulnerable to a denial-of-service (DoS) condition in its integrated SFTP server implementation. The vulnerability, identified as CVE-2026-52856, stems from improper input validation during the initial SFTP connection handshake. A remote, unauthenticated attacker can send a specifically crafted network packet that causes an uncaught exception (Go panic) within the application's runtime. This leads to the immediate termination of the Wings process, rendering the management agent unavailable. This vulnerability affects all versions of Pterodactyl Wings prior to 1.13.0. Defenders should note that because the crash occurs during the early handshake phase, the attack does not require valid credentials or an established session, making it highly accessible to remote actors.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify target servers exposing the Pterodactyl Wings SFTP port (default TCP 2022).\u003c/li\u003e\n\u003cli\u003eAttacker initiates an unauthenticated TCP connection to the identified SFTP port.\u003c/li\u003e\n\u003cli\u003eThe service begins the SFTP handshake process, expecting valid protocol headers.\u003c/li\u003e\n\u003cli\u003eAttacker transmits a maliciously crafted, malformed packet designed to bypass input validation filters.\u003c/li\u003e\n\u003cli\u003eThe application parses the malformed packet using vulnerable index-handling logic.\u003c/li\u003e\n\u003cli\u003eThe parsing logic triggers an uncaught exception or assertion failure within the Go runtime.\u003c/li\u003e\n\u003cli\u003eThe Go runtime triggers a panic, causing the Wings process to crash immediately.\u003c/li\u003e\n\u003cli\u003eFinal Objective: Successful denial of service against the Pterodactyl management infrastructure.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in the total loss of availability for the Pterodactyl Wings service. For environments hosting game servers, this results in the inability to manage, start, stop, or configure server instances. If an attacker systematically targets a fleet of Wings nodes, they can cause widespread administrative outages across an entire hosting environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Pterodactyl Wings to version 1.13.0 or later immediately to patch CVE-2026-52856.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, restrict access to the SFTP service port via firewall rules to known-only administrative IP addresses.\u003c/li\u003e\n\u003cli\u003eMonitor webserver/proxy logs or firewall connection logs for high-frequency or anomalous connection attempts directed at the SFTP port, which may indicate scanning or exploitation activity.\u003c/li\u003e\n\u003cli\u003eEnsure that process monitoring is configured to automatically restart the Wings service if it enters a non-running state.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-31T19:30:26Z","date_published":"2026-07-31T19:30:26Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wings-sftp-dos/","summary":"An unauthenticated remote attacker can trigger a panic and crash the Pterodactyl Wings service by sending a maliciously crafted packet during the SFTP handshake.","title":"Pterodactyl Wings SFTP Service Denial of Service","url":"https://feed.craftedsignal.io/briefs/2026-07-wings-sftp-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Wings","version":"https://jsonfeed.org/version/1.1"}