Denial of Service Vulnerability in PocketMine-MP by PocketMine Team
CVE-2022-51017
8.7HIGH
What is CVE-2022-51017?
PocketMine-MP, versions prior to 3.26.5 and 4.0.5, are susceptible to a denial of service vulnerability due to improper validation of player-submitted skin data fields. This flaw permits attackers to input excessively large values, surpassing the 32767 byte limit for TAG_String, which can result in unexpected exceptions during NBT data serialization. Consequently, this exploit can lead to a server crash, disrupting gameplay and affecting the server's availability.
