Denial of Service Vulnerability in PocketMine-MP by PMMP
CVE-2022-51008

6.9MEDIUM

Key Information:

Vendor

Pmmp

Vendor
CVE Published:
6 September 2026

What is CVE-2022-51008?

PocketMine-MP versions prior to 4.12.3 are vulnerable to a Denial of Service attack due to a failure to restrict unauthenticated sessions. Attackers can exploit this vulnerability by initiating multiple connections that do not require authentication, leading to the exhaustion of available player slots. This results in legitimate players being unable to connect, significantly disrupting server operations and user experience.

Affected Version(s)

PocketMine-MP 4.0.0 < 4.12.3

PocketMine-MP 4.12.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alvin0319
.