Multiple Pocketmine MP Vulnerabilities Lead to Denial of Service Risks

Multiple Pocketmine MP Vulnerabilities Lead to Denial of Service Risks

First seen 10 Sep 2026, 00:44 UTC www.vulncheck.com 58.5

Article Content

Browse articles
ThreatCluster

Recent advisories have identified several Denial of Service (DoS) vulnerabilities in Pocketmine MP, affecting versions before 5.11.1, 4.20.5, and 3.26.5/4.0.5. The vulnerabilities exploit the Loginpacket and Skin Data, allowing attackers to disrupt server operations. Affected systems include various iterations of Pocketmine MP, a popular server software for Minecraft. The vulnerabilities were disclosed on September 10, 2026, and September 7, 2026, with the potential for significant impact on server availability. Administrators are urged to prioritize patching to mitigate risks. No active exploitation has been confirmed, but the vulnerabilities are critical enough to warrant immediate attention.

Key Points: • Denial of Service vulnerabilities affect multiple Pocketmine MP versions. • Attack vectors include Loginpacket and Skin Data exploitation. • Patching is essential to prevent potential service disruptions.

Ask AI about this cluster

Timeline

2026-09-07
DoS vulnerability via Skin Data disclosed
Pocketmine MP versions before 3.26.5 and 4.0.5 are affected by a DoS vulnerability through Skin Data.
www.vulncheck.com
2026-09-10
Multiple DoS vulnerabilities disclosed
Advisories released for vulnerabilities in Pocketmine MP versions before 5.11.1 and 4.20.5, affecting server stability.
www.vulncheck.com
2026-09-10
Additional vulnerability identified
A new DoS vulnerability via Loginpacket Clientdata was disclosed for versions before 5.41.1.
www.vulncheck.com
2026-09-10
Server crash vulnerability disclosed
A vulnerability in Pocketmine MP 5.2.0 was reported, causing server crashes due to incorrect EC curve handling.
www.vulncheck.com