Uncaught Exception Vulnerability in PocketMine-MP Server Software
CVE-2022-51014

7.1HIGH

Key Information:

Vendor

Pmmp

Vendor
CVE Published:
7 September 2026

What is CVE-2022-51014?

The PocketMine-MP software prior to version 4.0.7 is susceptible to an unhandled exception vulnerability due to improper processing of malformed JSON from client form responses. Attackers can exploit this flaw by sending specially crafted response packets containing invalid JSON data, triggering an unhandled InvalidArgumentException that leads to server crashes. This vulnerability poses significant risks to server stability and availability, requiring prompt attention to mitigate such potential service interruptions.

Affected Version(s)

PocketMine-MP 0 < 4.0.7

PocketMine-MP 4.0.7

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.