| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fgmm-w5cx-vrfw | Pterodactyl has a database resource limit bypass via race condition in Client API |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 03 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pterodactyl
Pterodactyl panel |
|
| Vendors & Products |
Pterodactyl
Pterodactyl panel |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has a logic flaw that lets users bypass their assigned limits for database allocations. This happens because the database locking mechanism used in the controllers is totally broken and doesn't actually lock anything. Version 1.12.3 patches the issue. | |
| Title | Pterodactyl has a database resource limit bypass via race condition in Client API | |
| Weaknesses | CWE-367 CWE-770 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-03T12:47:52.123Z
Reserved: 2026-04-01T18:48:58.937Z
Link: CVE-2026-35202
Updated: 2026-06-03T12:47:48.582Z
Status : Received
Published: 2026-06-02T20:16:35.143
Modified: 2026-06-02T20:16:35.143
Link: CVE-2026-35202
No data.
OpenCVE Enrichment
Updated: 2026-06-03T05:45:26Z
Github GHSA