Search Results (7 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-86200 1 Pmmp 1 Pocketmine-mp 2026-09-18 5.3 Medium
PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to flood warning messages by injecting numerous junk properties into the clientData JWT. Attackers can craft malicious login packets with excessive unknown properties to waste server CPU time and degrade performance.
CVE-2026-86201 1 Pmmp 1 Pocketmine-mp 2026-09-14 7.5 High
PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in unknown clientData JWT properties cause excessive logging without sanitization. Attackers can send crafted LoginPackets with deeply nested or massive object structures to trigger out-of-memory conditions and crash the server.
CVE-2026-86198 1 Pmmp 1 Pocketmine-mp 2026-09-10 4.2 Medium
PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedly trigger pre-spawn progression, creating duplicate Player objects and amplifying memory consumption and network traffic.
CVE-2026-86203 1 Pmmp 1 Pocketmine-mp 2026-09-10 3.7 Low
PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing inventory items and experience to drop multiple times for duplication.
CVE-2026-86199 1 Pmmp 1 Pocketmine-mp 2026-09-10 7.5 High
PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline login authentication. Unauthenticated players can trigger an uninitialized property access error that crashes the server.
CVE-2026-86202 1 Pmmp 1 Pocketmine-mp 2026-09-10 4.3 Medium
PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messages to spam animation events to other clients and waste server CPU and memory resources.
CVE-2026-86204 1 Pmmp 1 Pocketmine-mp 2026-09-10 6.5 Medium
PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players to cause denial of service. Attackers can send modal form response packets with massive JSON arrays to exhaust server memory and CPU resources, rendering the server unresponsive.