Multiple CVEs Discovered in PocketMine-MP Affecting Game Server Availability

Multiple CVEs Discovered in PocketMine-MP Affecting Game Server Availability

First seen 10 Sep 2026, 00:44 UTC Redpacketsecuritygithub.com 57.8

Article Content

Browse articles
ThreatCluster

Five critical vulnerabilities were identified in PocketMine-MP, affecting versions prior to 5.41.1. CVE-2022-51017 and CVE-2023-54355 allow attackers to crash servers through malformed skin data and LoginPackets, respectively. CVE-2024-58381 and CVE-2023-54393 exploit improper JSON handling to trigger server crashes. CVE-2026-86201 involves denial of service through excessive logging from crafted LoginPackets. All vulnerabilities pose high operational risks for publicly reachable servers, particularly those accepting connections from untrusted players. The vulnerabilities were disclosed on September 7 and September 9, 2026, but there is no confirmed active exploitation. Administrators are urged to apply patches promptly to mitigate risks.

Key Points: • Five critical vulnerabilities in PocketMine-MP affect game server availability. • Attackers can exploit malformed data to crash servers without authentication. • Immediate patching is recommended to prevent service disruptions.

Ask AI about this cluster

Timeline

2026-09-07
CVE-2022-51017 published
PocketMine-MP versions before 3.26.5 and 4.0.5 are vulnerable to denial of service via oversized skin data.
Redpacketsecurity
2026-09-09
CVE-2023-54355 published
Vulnerability in LoginPacket processing allows attackers to crash servers with malformed keys.
Redpacketsecurity
2026-09-09
CVE-2026-86201 published
Denial of service vulnerability in LoginPacket processing due to excessive logging from crafted data.
Redpacketsecurity
2026-09-09
CVE-2024-58381 published
Improper JSON processing in LoginPacket allows attackers to crash servers with malformed data.
Redpacketsecurity
2026-09-09
CVE-2023-54393 published
Denial of service vulnerability in LoginPacket JSON parsing due to improper validation.
Redpacketsecurity