← Terug naar overzicht

PocketMine-MP versions prior to 3.26.5 and 4.0.5 contain a vulnerability where skin data fields submitted by players are not properly validated for length. This allows attackers to submit oversized values that exceed the 32767 byte TAG_String limit used in NBT data serialization. Fields such as skinID and geometryName can be exploited by sending oversized data, triggering exceptions during NBT serialization and causing server crashes. The vulnerability enables unauthenticated remote attackers to perform denial-of-service attacks against PocketMine-MP game servers. Fixes were introduced in versions 3.26.5 and 4.0.5 with proper input length validation.

Affected products

  • PocketMine-MP

Related CVE's

  • CVE-2022-51017

Categories

  • Mobile & IoT
  • Web Technologies