pocketmine/pocketmine-mp
Packagist30 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting pocketmine/pocketmine-mppage 1 of 1
- CVE-2020-37277MEDIUMCVSS 6.5EG 6.5✓ Fixed in 3.15.42026-09-06
vulnerable: 3.0.0 ... 3.9.8 (108 versions)
PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflict…
- CVE-2021-48006LOWCVSS 3.3EG 3.3✓ Fixed in 4.0.32026-09-06
vulnerable: 3.0.0 ... 4.0.2 (171 versions)
PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an exactly matching entry, so an operator name stored wi…
- CVE-2021-48007MEDIUMCVSS 6.5EG 6.5✓ Fixed in 3.18.12026-09-06
vulnerable: 3.0.0 ... 3.9.8 (120 versions)
PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-point values to crash servers through unhan…
- CVE-2022-51009HIGHCVSS 7.5EG 7.5✓ Fixed in 4.7.22026-09-06
vulnerable: 3.0.0 ... 4.7.1 (209 versions)
PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeExcep…
- CVE-2022-51010MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.4.22026-09-07
vulnerable: 4.0.0 ... 4.4.1 (43 versions)
PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the valid range to trigger an uncaught exception that crashes the server.
- CVE-2022-51011MEDIUMCVSS 4.3EG 4.3✓ Fixed in 4.2.102026-09-07
vulnerable: 3.0.0 ... 4.2.9 (191 versions)
PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large messages containing many newlines. Malicious clients can send megab…
- CVE-2022-51012MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.2.92026-09-07
vulnerable: 3.0.0 ... 4.2.8 (190 versions)
PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger server …
- CVE-2022-51013MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.2.42026-09-07
vulnerable: 3.0.0 ... 4.2.3 (185 versions)
PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-range damage values in itemstack NBT to trigger unhandled exceptions i…
- CVE-2022-51014MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.0.72026-09-07
vulnerable: 4.0.0 ... 4.0.6 (7 versions)
PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can send specially crafted form response packets with invalid JSON to tr…
- CVE-2022-51015MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.0.62026-09-07
vulnerable: 3.0.0 ... 4.0.5 (174 versions)
PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in UseItemTransactionData (typically within InventoryTransactionPacket). A remote authenticated attacker can send…
- CVE-2022-51016MEDIUMCVSS 6.1EG 6.1✓ Fixed in 4.0.02026-09-07
vulnerable: 3.0.0 ... 4.0.0-BETA9 (168 versions)
PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key corresponding to its login token. An attacker who captures a valid l…
- CVE-2022-51017HIGHCVSS 7.5EG 7.5✓ Fixed in 4.0.52026-09-07
vulnerable: 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4
PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit. Attackers can submit oversized skin data fields like s…
- CVE-2022-51018MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.0.52026-09-07
vulnerable: 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4
PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create oversized NBT ('book bombs'), causing excess bandwidth consumption…
- CVE-2023-54355HIGHCVSS 7.5EG 7.5✓ Fixed in 5.3.12026-09-09
vulnerable: 5.2.0, 5.2.1, 5.3.0
PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1 elliptic curve. Attackers can provide LoginPackets with keys using different curves or non-EC key types t…
- CVE-2023-54390HIGHCVSS 7.5EG 7.5✓ Fixed in 5.3.12026-09-09
vulnerable: 5.0.0 ... 5.3.0 (9 versions)
PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper null value handling in arrays. Attackers can send malformed JSON with unexpected null elements in LoginPac…
- CVE-2023-54392MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.22.32026-09-09
vulnerable: 4.20.0 ... 4.22.2 (11 versions)
PocketMine-MP versions >= 4.20.0 before 4.22.3 (and before 5.2.1 in the 5.x branch) fail to validate NBT tag types in BlockActorDataPacket. A player can crash the server by sending a packet containing sign NBT data with an incorrect tag ty…
- CVE-2023-54393HIGHCVSS 7.5EG 7.5✓ Fixed in 4.20.52026-09-09
vulnerable: 3.0.0 ... 4.9.1 (263 versions)
PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in the JsonMapper dependency. Attackers can send malformed JSON structures in LoginPacket to crash the se…
- CVE-2023-54394MEDIUMCVSS 4.3EG 4.3✓ Fixed in 4.18.0-ALPHA22026-09-09
vulnerable: 3.0.0 ... 4.9.1 (248 versions)
PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allowing attackers to trigger excessive inventory synchronization. Attackers can send numerous mismatch transactions to force the ser…
- CVE-2023-54395MEDIUMCVSS 4.3EG 4.3✓ Fixed in 4.12.52026-09-09
vulnerable: 3.0.0 ... 4.9.1 (226 versions)
PocketMine-MP versions before 4.12.5 contain a denial-of-service vulnerability in ModalFormResponsePacket processing that allows attackers to cause server resource exhaustion by sending large JSON payloads. Attackers can send numerous over…
- CVE-2023-54396MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.8.12026-09-09
vulnerable: 3.0.0 ... 4.8.0 (212 versions)
PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide invalid color values in inventory transactions or via commands to trigger undefined offset errors and crash…
- CVE-2023-7332HIGHCVSS 7.1EG 7.1✓ Fixed in 4.18.12025-12-31
vulnerable: 3.0.0 ... 4.9.1 (250 versions)
PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can request that the server drop more items than are available in th…
- CVE-2024-58380MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.11.22026-09-09
vulnerable: 3.0.0 ... 5.9.0 (323 versions)
PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes the server when an invalid inventory slot value is provided. Attackers can send a crafted BookEditPacket with an invento…
- CVE-2024-58381HIGHCVSS 7.5EG 7.5✓ Fixed in 5.11.12026-09-09
vulnerable: 3.0.0 ... 5.9.0 (322 versions)
PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization fro…
- CVE-2025-71417MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.32.12026-09-09
vulnerable: 3.0.0 ... 5.9.0 (361 versions)
PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions. Attackers can send multiple copi…
- CVE-2025-71418MEDIUMCVSS 5.3EG 5.3✓ Fixed in 5.25.22026-09-09
vulnerable: 3.0.0 ... 5.9.0 (349 versions)
PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing, allowing malicious clients to waste server resources. Attackers can send crafted packets with excessive delimiters to consume CPU and memory throu…
- CVE-2026-86200MEDIUMCVSS 5.3EG 5.3✓ Fixed in 5.42.12026-09-09
vulnerable: 3.0.0 ... 5.9.0 (383 versions)
PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to flood warning messages by injecting numerous junk properties into the clientData JWT. Attackers can c…
- CVE-2026-86201HIGHCVSS 7.5EG 7.5✓ Fixed in 5.41.12026-09-09
vulnerable: 3.0.0 ... 5.9.0 (381 versions)
PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in unknown clientData JWT properties cause excessive logging without sanitization. Attackers can send crafte…
- CVE-2026-86202MEDIUMCVSS 4.3EG 4.3✓ Fixed in 5.39.22026-09-09
vulnerable: 3.0.0 ... 5.9.0 (377 versions)
PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messag…
- CVE-2026-86203LOWCVSS 3.7EG 3.7✓ Fixed in 5.39.22026-09-09
vulnerable: 3.0.0 ... 5.9.0 (377 versions)
PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing …
- CVE-2026-86204MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.39.22026-09-09
vulnerable: 3.0.0 ... 5.9.0 (377 versions)
PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players to cause denial of service. Attackers can send modal form response packets with massive JSON arrays to…
Check whether pocketmine/pocketmine-mp is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for pocketmine/pocketmine-mp CVEs against the assets you own.
Start Free Scan →