PT-2026-66783 · Wings · Wings

CVE-2026-52856

·

Published

2026-07-31

·

Updated

2026-09-04

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wings versions prior to 1.13.0
Description A malformed packet received and parsed during the SFTP connection handshake causes a Go panic, which is a runtime error in the Go programming language that crashes the program.
Recommendations Update to version 1.13.0. Close the SFTP port as a temporary workaround.

Exploit

Fix

Improper Validation of Array Index

RCE

Assertion Failure

Resource Exhaustion

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-52856
GHSA-GHRQ-5WPP-HXX5
GO-2026-6156
OPENSUSE-SU-2026:21761-1

Affected Products

Wings