CVE-2020-37277
PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.
- Published Sep 6, 2026
- CVSS 7.1 high
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available