CVE-2021-48007
PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-point values to crash servers through unhandled mathematical operations or prevent clients from rendering other players.
- Published Sep 6, 2026
- CVSS 7.1 high
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available