pmmp PocketMine-MP
32 known vulnerabilities in pmmp PocketMine-MP, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-86204 CVSS 7.1 high PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players…
- CVE-2026-86203 CVSS 6.3 medium PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can…
- CVE-2026-86202 CVSS 5.3 medium PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to…
- CVE-2026-86201 CVSS 8.7 high PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in…
- CVE-2026-86200 CVSS 6.9 medium PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to…
- CVE-2026-86199 CVSS 8.7 high PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline login authentication. Unauthenticated…
- CVE-2026-86198 CVSS 2.3 low PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED…
- CVE-2025-71418 CVSS 6.9 medium PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing, allowing malicious clients to waste server…
- CVE-2025-71417 CVSS 7.1 high PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling…
- CVE-2024-58381 CVSS 8.7 high PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to…
- CVE-2024-58380 CVSS 7.1 high PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes the server when an…
- CVE-2023-54396 CVSS 7.1 high PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide…
- CVE-2023-54395 CVSS 5.3 medium PocketMine-MP versions before 4.12.5 contain a denial-of-service vulnerability in ModalFormResponsePacket processing that allows attackers…
- CVE-2023-54394 CVSS 5.3 medium PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allowing attackers to trigger…
- CVE-2023-54393 CVSS 8.7 high PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in…
- CVE-2023-54392 CVSS 7.1 high PocketMine-MP versions >= 4.20.0 before 4.22.3 (and before 5.2.1 in the 5.x branch) fail to validate NBT tag types in…
- CVE-2023-54390 CVSS 8.7 high PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper null…
- CVE-2023-54355 CVSS 8.7 high PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1…
- CVE-2022-51018 CVSS 7.1 high PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who…
- CVE-2022-51017 CVSS 8.7 high PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped…
- CVE-2022-51016 CVSS 5.3 medium PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting…
- CVE-2022-51015 CVSS 7.1 high PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in…
- CVE-2022-51014 CVSS 7.1 high PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed…
- CVE-2022-51013 CVSS 7.1 high PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients…
- CVE-2022-51012 CVSS 7.1 high PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from…
- CVE-2022-51011 CVSS 5.3 medium PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters…
- CVE-2022-51010 CVSS 7.1 high PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send…
- CVE-2022-51009 CVSS 8.7 high PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data…
- CVE-2022-51008 CVSS 6.9 medium PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions…
- CVE-2021-48007 CVSS 7.1 high PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious…