Denial of Service in PocketMine-MP due to Improper NBT Data Validation
CVE-2022-51012

7.1HIGH

Key Information:

Vendor

Pmmp

Vendor
CVE Published:
7 September 2026

What is CVE-2022-51012?

PocketMine-MP versions prior to 4.2.9 are vulnerable to denial of service attacks due to inadequate validation of NBT data types during the deserialization of inventory transaction packets. Attackers can exploit this vulnerability by sending specially crafted inventory transactions with improperly formatted NBT tags, leading to server crashes and unavailability. It is crucial for users of affected versions to update to 4.2.9 or later to mitigate the risks associated with this vulnerability.

Affected Version(s)

PocketMine-MP 0 < 4.2.9

PocketMine-MP 4.2.9

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.