Redpacketsecurity
Multiple CVEs Discovered in PocketMine-MP Affecting Game Server Availability
Article Content
Five critical vulnerabilities were identified in PocketMine-MP, affecting versions prior to 5.41.1. CVE-2022-51017 and CVE-2023-54355 allow attackers to crash servers through malformed skin data and LoginPackets, respectively. CVE-2024-58381 and CVE-2023-54393 exploit improper JSON handling to trigger server crashes. CVE-2026-86201 involves denial of service through excessive logging from crafted LoginPackets. All vulnerabilities pose high operational risks for publicly reachable servers, particularly those accepting connections from untrusted players. The vulnerabilities were disclosed on September 7 and September 9, 2026, but there is no confirmed active exploitation. Administrators are urged to apply patches promptly to mitigate risks.
Key Points: • Five critical vulnerabilities in PocketMine-MP affect game server availability. • Attackers can exploit malformed data to crash servers without authentication. • Immediate patching is recommended to prevent service disruptions.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.