Denial of Service Vulnerability in PocketMine-MP by PocketMine Team
CVE-2022-51017

8.7HIGH

Key Information:

Vendor

Pmmp

Vendor
CVE Published:
7 September 2026

What is CVE-2022-51017?

PocketMine-MP, versions prior to 3.26.5 and 4.0.5, are susceptible to a denial of service vulnerability due to improper validation of player-submitted skin data fields. This flaw permits attackers to input excessively large values, surpassing the 32767 byte limit for TAG_String, which can result in unexpected exceptions during NBT data serialization. Consequently, this exploit can lead to a server crash, disrupting gameplay and affecting the server's availability.

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.