CVE-2025-69198: Pterodactyl's improper resource locking allows raced queries to create more resources than alloted

Published Jan 19, 2026
·
Updated

Summary Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocations, or backups) that can exist for an individual server. These resource limits are applied on a per-server basis, and validated during the request cycle.

However, it is possible for a malicious user to send a massive volume of requests at the same time that would create more resources than the server is allotted. This is because the validation occurs early in the request cycle and does not lock the target resource while it is processing. As a result sending a large volume of requests at the same time would lead all of those requests to validate as not using any of the target resources, and then all creating the resources at the same time.

As a result a server would be able to create more databases, allocations, or backups than configured.

Impact A malicious user is able to deny resources to other users on the system, and may be able to excessively consume the limited allocations for a node, or fill up backup space faster than is allowed by the system.

Other sources

Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocations, or backups) that can exist for an individual server. These resource limits are applied on a per-server basis, and validated during the request cycle. However, in versions prior to 1.12.0, it is possible for a malicious user to send a massive volume of requests at the same time that would create more resources than the server is allotted. This is because the validation occurs early in the request cycle and does not lock the target resource while it is processing. As a result sending a large volume of requests at the same time would lead all of those requests to validate as not using any of the target resources, and then all creating the resources at the same time. As a result a server would be able to create more databases, allocations, or backups than configured. A malicious user is able to deny resources to other users on the system, and may be able to excessively consume the limited allocations for a node, or fill up backup space faster than is allowed by the system. Version 1.12.0 fixes the issue.

MITRE

Affected Software

3 affected componentsFixes available
pypi/pterodactyl<1.12.0
composer/pterodactyl/panel<1.12.0
1.12.0
pterodactyl panel<1.12.0

Event History

Jan 19, 2026
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
RemedyAffected Software
Jan 20, 2026
Advisory Published
via GitHub·04:30 PM
Data Sourced
via GitHub·04:30 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-69198?

CVE-2025-69198 has been categorized as a high-severity vulnerability due to its potential to allow resource over-allocation.

2

How do I fix CVE-2025-69198?

To fix CVE-2025-69198, update Pterodactyl to version 1.12.0 or later to ensure proper resource locking.

3

What kind of resources are affected by CVE-2025-69198?

CVE-2025-69198 affects resources such as databases, port allocations, and backups within the Pterodactyl management panel.

4

What can happen if CVE-2025-69198 is exploited?

If exploited, CVE-2025-69198 could lead to the creation of more resources than allocated, potentially causing server instability.

5

Is CVE-2025-69198 specific to certain versions of Pterodactyl?

Yes, CVE-2025-69198 specifically affects versions of Pterodactyl up to, but not including, version 1.12.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203