← Vulnerability feed

Vulnerability record · CVE-2025-69198 · published 19 January 2026

CVE-2025-69198: Pterodactyl panel uncontrolled resource consumption vulnerability

Pterodactyl · Panel

Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocations, or backups) that can exist for an individual server. These resource limits are applied on a per-server basis, and validated during the request cycle. However, in versions prior to 1.12.0, it is possible for a malicious user to send a massive volume of requests at the same time that would create more resources than the server is allotted. This is because the validation occurs early in the request cycle and does not lock the target resource while it is processing. As a result sending a large volume of requests at the same time would lead all of those requests to validate as not using any of the target resources, and then all creating the resources at the same time. As a result a server would be able to create more databases, allocations, or backups than configured. A malicious user is able to deny resources to other users on the system, and may be able to excessively consume the limited allocations for a node, or fill up backup space faster than is allowed by the system. Version 1.12.0 fixes the issue.

6.0 CVSS 4.0 Medium EPSS 0.24% · top 86.2% CWE-400 · Uncontrolled resource consumptionCWE-413 · CWE-413
6.0CVSS 4.0 base score
0.24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocations, or backups) that can exist for an individual server. These resource limits are applied on a per-server basis, and validated during the request cycle. However, in versions prior to 1.12.0, it is possible for a malicious user to send a massive volume of requests at the same time that would create more resources than the server is allotted. This is because the validation occurs early in the request cycle and does not lock the target resource while it is processing. As a result sending a large volume of requests at the same time would lead all of those requests to validate as not using any of the target resources, and then all creating the resources at the same time. As a result a server would be able to create more databases, allocations, or backups than configured. A malicious user is able to deny resources to other users on the system, and may be able to excessively consume the limited allocations for a node, or fill up backup space faster than is allowed by the system. Version 1.12.0 fixes the issue.

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-69198 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.2CVE-2026-26016Pterodactyl panel insecure direct object reference vulnerabilityWings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization…EPSS 0.46%8.1CVE-2021-41129Pterodactyl panel deserialization of untrusted data vulnerabilityPterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmati…EPSS 1.8%7.5CVE-2025-68954Pterodactyl panel insufficient session expiration vulnerabilityPterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is remo…EPSS 0.25%7.5CVE-2019-1020002Pterodactyl panel observable discrepancy vulnerabilityPterodactyl before 0.7.14 with 2FA allows credential sniffing.EPSS 1.5%6.5CVE-2025-69197Pterodactyl panel improper authentication vulnerabilityPterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity …EPSS 0.36%6.1CVE-2024-34067Pterodactyl panel cross-site scripting vulnerabilityPterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings i…EPSS 0.46%4.3CVE-2021-41273Pterodactyl panel cross-site request forgery vulnerabilityPterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two rout…EPSS 0.39%4.3CVE-2021-41176Pterodactyl panel cross-site request forgery vulnerabilityPterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can …EPSS 0.52%

Source: NIST National Vulnerability Database (record CVE-2025-69198), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.