Summary
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
Advisory details
Summary
A maliciously crafted packet received & parsed during the SFTP connection handshake will cause a Go panic.
Impact
All wings users with an open SFTP port.
Workarounds
Close SFTP port.
References
Related vulnerabilities
All Supply chain →- MEDIUMGHSA-rgqc-3x5p-6gwg
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
- HIGHGHSA-pfvm-w89x-94jw
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
- MEDIUMCVE-2026-65834
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
- HIGHCVE-2026-54632
SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)
- MEDIUMCVE-2026-14631
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
- MEDIUMCVE-2026-53496
ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes