Denial of Service Vulnerability in PocketMine-MP by PMMP
CVE-2021-48007

7.1HIGH

Key Information:

Vendor

Pmmp

Vendor
CVE Published:
6 September 2026

What is CVE-2021-48007?

Earlier versions of PocketMine-MP, specifically those prior to 3.18.1, exhibit a flaw in validating floating-point values in MovePlayerPacket's position and rotation fields. This vulnerability allows malicious clients to exploit the server by sending specially crafted movement packets containing invalid NaN or INF values. Such packets can trigger unhandled mathematical operations, resulting in server crashes or rendering issues for clients unable to see other players.

Affected Version(s)

PocketMine-MP 0 < 3.18.1

PocketMine-MP 3.18.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.