Improper Resource Locking Affecting pterodactyl/panel package, versions <1.12.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-PTERODACTYLPANEL-15037181
  • published20 Jan 2026
  • disclosed19 Jan 2026
  • creditВсеволод Мельник

Introduced: 19 Jan 2026

CVE-2025-69198  (opens in a new tab)
CWE-413  (opens in a new tab)

How to fix?

Upgrade pterodactyl/panel to version 1.12.0 or higher.

Overview

pterodactyl/panel is a game management panel.

Affected versions of this package are vulnerable to Improper Resource Locking due to the validation occuring early in the request cycle and not locking the target resource while it is processing. An attacker can exhaust system resources and deny service to other users by sending a high volume of simultaneous requests that bypass allocation limits.

References

CVSS Base Scores

version 4.0
version 3.1