Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fgmm-w5cx-vrfw | Pterodactyl has a database resource limit bypass via race condition in Client API |
Wed, 03 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pterodactyl
Pterodactyl panel |
|
| Vendors & Products |
Pterodactyl
Pterodactyl panel |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has a logic flaw that lets users bypass their assigned limits for database allocations. This happens because the database locking mechanism used in the controllers is totally broken and doesn't actually lock anything. Version 1.12.3 patches the issue. | |
| Title | Pterodactyl has a database resource limit bypass via race condition in Client API | |
| Weaknesses | CWE-367 CWE-770 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-03T12:47:52.123Z
Reserved: 2026-04-01T18:48:58.937Z
Link: CVE-2026-35202
Updated: 2026-06-03T12:47:48.582Z
Status : Deferred
Published: 2026-06-02T20:16:35.143
Modified: 2026-06-04T16:12:56.200
Link: CVE-2026-35202
No data.
OpenCVE Enrichment
Updated: 2026-06-03T05:45:26Z
Github GHSA